57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3491 | MED 5.5 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct a cross-site scripting (XSS) attack against a user of the interface on an aff | 0.6% | — |
| CVE-2020-3464 | MED 4.8 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists b | 0.6% | — |
| CVE-2020-26083 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vuln | 0.6% | — |
| CVE-2020-10732 | LOW 3.3 | canonical ubuntu_linux A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | 0.6% | — |
| CVE-2016-6375 | MED 5.3 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and the | 0.6% | — |
| CVE-2004-2013 | HIGH 7.8 | linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. | 0.6% | — |
| CVE-2026-78519 | HIGH 8.8 | microsoft 365_apps Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-55002 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-52986 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request() with a new sip_parse_port() helper th | 0.6% | — |
| CVE-2026-32183 | HIGH 7.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-0391 | MED 6.5 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-55676 | MED 5.5 | microsoft windows_11_24h2 Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21275 | HIGH 7.8 | microsoft windows_10_21h2 Windows App Package Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43571 | MED 5.6 | microsoft windows_11_24h2 Sudo for Windows Spoofing Vulnerability | 0.6% | — |
| CVE-2024-35870 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in smb2_reconnect_server() The UAF bug is due to smb2_reconnect_server() accessing a session that is already being teared down by another thread that is executing __cifs | 0.6% | — |
| CVE-2022-49003 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme: fix SRCU protection of nvme_ns_head list Walking the nvme_ns_head siblings list is protected by the head's srcu in nvme_ns_head_submit_bio() but not nvme_mpath_revalidate_paths(). Remo | 0.6% | — |
| CVE-2022-38017 | MED 6.8 | microsoft storsimple_8010_firmware StorSimple 8000 Series Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-26625 | HIGH 8.8 | tobesoft nexacro Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers | 0.6% | — |
| CVE-2021-20543 | MED 5.4 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IB | 0.6% | — |
| CVE-2026-9182 | CRIT 9.8 | esri arcgis_server Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing fo | 0.6% | — |
| CVE-2026-52844 | HIGH 7.5 | caddyserver caddy Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenti | 0.6% | — |
| CVE-2026-45650 | MED 4.3 | microsoft bing User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-21261 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-21258 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |