58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-2328 | HIGH 7.1 | microsoft windows_2000 Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request. | 16.6% | — |
| CVE-2002-1222 | HIGH 7.1 | cisco catos Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request. | 8.6% | — |
| CVE-2002-1024 | HIGH 7.1 | cisco catos Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144). | 3.3% | — |
| CVE-2002-0813 | HIGH 7.1 | cisco ios Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename. | 9.1% | — |
| CVE-2001-0427 | HIGH 7.1 | cisco vpn_3000_concentrator Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed logi | 2.5% | — |
| CVE-2001-0006 | HIGH 7.1 | microsoft windows_nt The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Wins | 3.0% | — |
| CVE-2000-0380 | HIGH 7.1 | cisco ios The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. | 35.0% | — |
| CVE-1999-0725 | HIGH 7.1 | microsoft internet_information_server When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | 24.9% | — |
| CVE-1999-0723 | HIGH 7.1 | microsoft windows_2000 The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. | 7.3% | — |
| CVE-2026-98083 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-after-free in raid stripe insertion If allocation of a RAID stripe extent fails, btrfs_insert_one_raid_extent() aborts and ends the transaction before returning -E | 0.1% | — |
| CVE-2026-85360 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83999 | HIGH 7.0 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83940 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-81389 | HIGH 7.0 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-80093 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-78464 | HIGH 7.0 | microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-78457 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77905 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77899 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77897 | HIGH 7.0 | microsoft power_automate_for_desktop Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77894 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77485 | HIGH 7.0 | microsoft sql_server_2017 Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-73022 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-73005 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73003 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |