57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-49703 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-0103 | HIGH 8.8 | paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers | 0.6% | — |
| CVE-2024-47504 | HIGH 7.5 | juniper junos An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). When a non-clustered SRX500 | 0.6% | — |
| CVE-2024-29008 | MED 6.4 | apache cloudstack A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM conf | 0.6% | — |
| CVE-2023-20215 | MED 5.8 | cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability i | 0.6% | — |
| CVE-2021-29770 | MED 6.5 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. | 0.6% | — |
| CVE-2019-3016 | MED 6.2 | linux linux_kernel In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later | 0.6% | — |
| CVE-2019-19231 | HIGH 7.3 | broadcom ca_client_automation An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges. | 0.6% | — |
| CVE-2019-1235 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'. | 0.6% | — |
| CVE-2026-65667 | CRIT 10.0 | microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-61484 | CRIT 9.8 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to | 0.6% | — |
| CVE-2026-40421 | MED 4.3 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-29977 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-53209 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix receive ring space parameters when XDP is active The MTU setting at the time an XDP multi-buffer is attached determines whether the aggregation ring will be used and the rx_skb_ | 0.6% | — |
| CVE-2024-48944 | MED 6.5 | apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The atta | 0.6% | — |
| CVE-2023-52991 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer in skb_segment_list Commit 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.") introduced UDP listifyed GRO. The segmentation relies on frag_list being untouched w | 0.6% | — |
| CVE-2020-12770 | MED 6.7 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | 0.6% | — |
| CVE-2014-4632 | MED 4.3 | vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which | 0.6% | — |
| CVE-2012-6533 | MED 4.4 | symantec encryption_desktop Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application. | 0.6% | — |
| CVE-2026-33454 | CRIT 9.4 | apache camel The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direc | 0.6% | — |
| CVE-2026-26128 | HIGH 7.8 | microsoft windows_10_1607 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-0287 | HIGH 7.5 | paloaltonetworks cloud_ngfw Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interfac | 0.6% | — |
| CVE-2025-64657 | CRIT 9.8 | microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-64656 | CRIT 9.4 | microsoft azure_application_gateway Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-47969 | MED 4.4 | microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. | 0.6% | — |