58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-29221 | HIGH 7.0 | erlang erlang\/otp A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service | 0.6% | — |
| CVE-2020-7874 | HIGH 8.8 | tobesoft nexacro Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or f | 0.6% | — |
| CVE-2019-13648 | MED 5.5 | linux linux_kernel In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service (TM Bad Thing exception and system crash) via a sigreturn() system call that sends a crafted signal frame. Thi | 0.6% | — |
| CVE-2026-34626 | MED 6.3 | adobe acrobat Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the conte | 0.6% | — |
| CVE-2025-53843 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via speciall | 0.6% | — |
| CVE-2025-49722 | MED 5.7 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2025-33074 | HIGH 7.5 | microsoft azure_functions Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-30376 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-30375 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0.6% | — |
| CVE-2024-21423 | MED 4.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-3619 | LOW 3.5 | linux linux_kernel A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended | 0.6% | — |
| CVE-2022-35717 | HIGH 7.8 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361. | 0.6% | — |
| CVE-2022-34165 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks again | 0.6% | — |
| CVE-2022-22746 | MED 5.9 | mozilla firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Fi | 0.6% | — |
| CVE-2021-39011 | MED 4.2 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645. | 0.6% | — |
| CVE-2019-19051 | MED 5.5 | canonical ubuntu_linux A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7. | 0.6% | — |
| CVE-2026-59085 | CRIT 9.1 | apache cloudstack Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended | 0.6% | — |
| CVE-2025-59489 | HIGH 7.4 | unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run | 0.6% | — |
| CVE-2025-29811 | HIGH 7.8 | microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-49571 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg When receiving proposal msg in server, the field iparea_offset and the field ipv6_prefixes_cnt in proposal msg | 0.6% | — |
| CVE-2024-21611 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Juniper Flow | 0.6% | — |
| CVE-2023-41180 | MED 5.9 | apache nifi_minifi_c\+\+ Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, | 0.6% | — |
| CVE-2023-28237 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-38377 | MED 4.3 | fortinet fortianalyzer An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through | 0.6% | — |