56.561 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.561 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2024-50302 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be | 0.8% | |
| CVE-2023-20118 | MED 6.5 | cisco rv016_firmware A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability | 54.1% | |
| CVE-2018-8639 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 22.3% | |
| CVE-2024-49035 | HIGH 8.7 | microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | 1.3% | |
| CVE-2025-24989 | HIGH 8.2 | microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust | 1.7% | |
| CVE-2025-0111 | MED 6.5 | paloaltonetworks pan-os An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can gre | 1.9% | |
| CVE-2025-0108 | CRIT 9.1 | paloaltonetworks pan-os An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain | 98.5% | |
| CVE-2025-21418 | HIGH 7.8 | microsoft windows_10_1607 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 1.5% | |
| CVE-2025-21391 | HIGH 7.1 | microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability | 2.3% | |
| CVE-2024-21413 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 94.7% | |
| CVE-2022-23748 | HIGH 7.8 | audinate dante_application_library mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load mal | 8.5% | |
| CVE-2024-53104 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating | 3.3% | |
| CVE-2024-45195 | HIGH 7.5 | apache ofbiz Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | 100.0% | |
| CVE-2024-29059 | HIGH 7.5 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 98.6% | |
| CVE-2025-21335 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.4% | |
| CVE-2025-21334 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2025-21333 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 10.0% | |
| CVE-2024-55591 | CRIT 9.8 | ransomware fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via | 98.3% | |
| CVE-2024-3393 | HIGH 7.5 | paloaltonetworks pan-os A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger thi | 28.6% | |
| CVE-2024-35250 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 25.2% | |
| CVE-2024-49138 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 25.4% | |
| CVE-2024-38813 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | 17.4% | |
| CVE-2024-38812 | CRIT 9.8 | vmware cloud_foundation The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to | 54.6% | |
| CVE-2024-9474 | HIGH 7.2 | ransomware paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this | 94.8% | |
| CVE-2024-0012 | CRIT 9.8 | ransomware paloaltonetworks pan-os An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or | 99.7% |