58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-53795 | CRIT 9.1 | microsoft pc_manager Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-48003 | MED 6.8 | microsoft windows_10_1809 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.6% | — |
| CVE-2025-4613 | HIGH 8.8 | google web_designer Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template | 0.6% | — |
| CVE-2025-20344 | MED 6.5 | cisco nexus_dashboard A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. This vulnerability is due to insufficient validation of the contents of a ba | 0.6% | — |
| CVE-2024-23307 | MED 4.4 | linux linux_kernel Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow. | 0.6% | — |
| CVE-2024-20393 | HIGH 8.8 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists | 0.6% | — |
| CVE-2023-52801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to | 0.6% | — |
| CVE-2023-38161 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-48985 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix race on per-CQ variable napi work_done After calling napi_complete_done(), the NAPIF_STATE_SCHED bit may be cleared, and another CPU can start napi thread and access per-CQ va | 0.6% | — |
| CVE-2022-39959 | HIGH 7.8 | panini everest_engine Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\ | 0.6% | — |
| CVE-2022-39842 | MED 6.1 | debian debian_linux An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is | 0.6% | — |
| CVE-2022-28883 | LOW 3.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker. | 0.6% | — |
| CVE-2021-27064 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2020-6175 | MED 5.9 | citrix citrix_sd-wan_center Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. | 0.6% | — |
| CVE-2016-1467 | MED 6.5 | cisco videoscape_session_resource_manager Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | 0.6% | — |
| CVE-2015-5652 | HIGH 7.2 | python python Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime | 0.6% | — |
| CVE-2026-59654 | HIGH 7.5 | apache cloudstack Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to e | 0.6% | — |
| CVE-2026-42812 | CRIT 9.9 | apache polaris In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata fil | 0.6% | — |
| CVE-2026-41612 | MED 5.5 | microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-46858 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== | 0.6% | — |
| CVE-2024-27066 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not ca | 0.6% | — |
| CVE-2024-26585 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). | 0.6% | — |
| CVE-2023-36008 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21759 | LOW 3.3 | microsoft windows_10 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2014-0351 | MED 5.4 | fortinet fortios The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere wit | 0.6% | — |