57.655 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.655 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-20658 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36770 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-26211 | MED 6.8 | fortinet fortisoar An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | 0.7% | — |
| CVE-2021-41347 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-28349 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-28348 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2020-1364 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. | 0.7% | — |
| CVE-2020-12826 | MED 5.3 | canonical ubuntu_linux A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can s | 0.7% | — |
| CVE-2019-5592 | MED 5.9 | fortinet fortios_ips_engine Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, when configured with SSL Deep Inspection po | 0.7% | — |
| CVE-2019-1695 | MED 6.5 | cisco adaptive_security_appliance_software A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulne | 0.7% | — |
| CVE-2026-81383 | HIGH 7.4 | microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80091 | MED 6.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80087 | MED 6.5 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80086 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80084 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80082 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80078 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80076 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-72975 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-50686 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42895 | MED 6.5 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-42027 | CRIT 9.8 | apache opennlp Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully | 0.7% | — |
| CVE-2022-41085 | HIGH 7.5 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26797 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26794 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |