IT
58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-21896 HIGH 7.0 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0.6% —
CVE-2021-41348 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 0.6% —
CVE-2020-5876 HIGH 8.1 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur wh 0.6% —
CVE-2020-12770 MED 6.7 canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. 0.6% —
CVE-2016-3951 MED 4.6 canonical ubuntu_linux Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB desc 0.6% —
CVE-2016-3689 MED 4.6 canonical ubuntu_linux The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface. 0.6% —
CVE-2016-2187 MED 4.6 canonical ubuntu_linux The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. 0.6% —
CVE-2026-65128 HIGH 8.8 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. 0.6% —
CVE-2026-58177 HIGH 8.1 apache traffic_server The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. 0.6% —
CVE-2026-34191 CRIT 9.1 apache apr-util Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 0.6% —
CVE-2026-28373 CRIT 9.6 stackfield stackfield The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesys 0.6% —
CVE-2026-20953 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6% —
CVE-2025-50161 HIGH 7.3 microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-38566 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's k 0.6% —
CVE-2025-29796 MED 4.7 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0.6% —
CVE-2025-21374 MED 5.5 microsoft windows_10_1507 Windows CSC Service Information Disclosure Vulnerability 0.6% —
CVE-2024-53124 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Syzkaller reported this warning: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0 0.6% —
CVE-2024-20691 MED 4.7 microsoft windows_10_1507 Windows Themes Information Disclosure Vulnerability 0.6% —
CVE-2023-37934 MED 4.3 fortinet fortipam An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency. 0.6% —
CVE-2023-31436 HIGH 7.8 linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. 0.6% —
CVE-2023-0140 MED 6.5 google chrome Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Low) 0.6% —
CVE-2023-0139 MED 6.5 google chrome Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low) 0.6% —
CVE-2022-48697 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a use-after-free Fix the following use-after-free complaint triggered by blktests nvme/004: BUG: KASAN: user-memory-access in blk_mq_complete_request_remote+0xac/0x350 Read of si 0.6% —
CVE-2022-37995 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6% —
CVE-2021-39054 MED 5.4 ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's clic 0.6% —