58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37980 | HIGH 7.8 | microsoft windows_10 Windows DHCP Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29116 | MED 4.7 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-47178 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Avoid smp_processor_id() in preemptible code The BUG message "BUG: using smp_processor_id() in preemptible [00000000] code" was observed for TCMU devices with kernel conf | 0.6% | — |
| CVE-2021-38300 | HIGH 7.8 | debian debian_linux arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed th | 0.6% | — |
| CVE-2019-19160 | MED 5.7 | cabsoftware reportexpress_proplus Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). | 0.6% | — |
| CVE-2019-16232 | MED 4.1 | canonical ubuntu_linux drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. | 0.6% | — |
| CVE-2018-7740 | MED 5.5 | canonical ubuntu_linux The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call. | 0.6% | — |
| CVE-2018-15395 | MED 5.4 | cisco wireless_lan_controller_software A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this acce | 0.6% | — |
| CVE-2015-7359 | HIGH 7.8 | ciphershed ciphershed The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impers | 0.6% | — |
| CVE-2014-8133 | LOW 2.1 | linux linux_kernel arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, vi | 0.6% | — |
| CVE-2012-2136 | HIGH 7.2 | linux linux_kernel The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privil | 0.6% | — |
| CVE-2026-58187 | LOW 3.7 | apache traffic_server The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users | 0.6% | — |
| CVE-2026-58158 | MED 5.9 | apache traffic_server Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad | 0.6% | — |
| CVE-2026-58152 | MED 5.9 | apache traffic_server Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade | 0.6% | — |
| CVE-2026-33930 | MED 5.9 | apache traffic_server Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8 | 0.6% | — |
| CVE-2026-24015 | CRIT 9.8 | apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. | 0.6% | — |
| CVE-2025-47173 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-26675 | HIGH 7.8 | microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24044 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-23331 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability m | 0.6% | — |
| CVE-2025-20256 | MED 6.5 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands | 0.6% | — |
| CVE-2024-30347 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0.6% | — |
| CVE-2023-28286 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-20263 | MED 4.7 | cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters | 0.6% | — |
| CVE-2021-31208 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.6% | — |