57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43636 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-22267 | CRIT 9.3 | vmware fusion VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on th | 0.7% | — |
| CVE-2023-52669 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this | 0.7% | — |
| CVE-2023-21569 | MED 5.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 0.7% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-47307 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses- | 0.7% | — |
| CVE-2021-47267 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [i | 0.7% | — |
| CVE-2021-47109 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will | 0.7% | — |
| CVE-2021-42274 | MED 6.8 | microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-31951 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1690 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1689 | HIGH 7.8 | microsoft windows_10 Windows Multipoint Management Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1688 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1687 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1686 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1681 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1662 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1659 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2018-0324 | MED 6.7 | cisco network_functions_virtualization_infrastructure A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command paramet | 0.7% | — |
| CVE-2018-0259 | HIGH 8.8 | cisco mate_collector A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to | 0.7% | — |
| CVE-2017-13864 | MED 5.9 | apple icloud An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishand | 0.7% | — |
| CVE-2011-1305 | MED 6.8 | google chrome Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to linked lists and a database. | 0.7% | — |
| CVE-2026-34538 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected | 0.7% | — |
| CVE-2025-66169 | MED 5.3 | apache camel Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14. | 0.7% | — |
| CVE-2025-59250 | HIGH 8.1 | microsoft jdbc_driver_for_sql_server Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |