57.701 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.701 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1366 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Workflow Service improperly handles objects in memory, aka 'Windows Print Workflow Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1360 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1356 | HIGH 7.8 | microsoft windows_server_2012 An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1353 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE | 0.7% | — |
| CVE-2020-1085 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2019-11487 | HIGH 7.8 | canonical ubuntu_linux The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kern | 0.7% | — |
| CVE-2018-0165 | HIGH 7.4 | cisco ios_xe A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust buffers on an affected device, resulting in a denial of service (DoS) conditi | 0.7% | — |
| CVE-2017-12275 | HIGH 7.4 | cisco wireless_lan_controller_software A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a | 0.7% | — |
| CVE-2015-0735 | MED 6.8 | cisco unified_customer_voice_portal Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970. | 0.7% | — |
| CVE-2013-3472 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote attackers to hijack the authentication of arbitrary users for requests that make ELM modifications, aka Bug ID CS | 0.7% | — |
| CVE-2026-54120 | CRIT 9.9 | microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-54906 | HIGH 7.8 | microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-22039 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check i | 0.7% | — |
| CVE-2024-38079 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38070 | HIGH 7.8 | microsoft windows_10_1507 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-20321 | HIGH 8.6 | cisco nx-os A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP | 0.7% | — |
| CVE-2023-39228 | MED 5.3 | intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-28772 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow. | 0.7% | — |
| CVE-2022-45888 | MED 6.4 | linux linux_kernel An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | 0.7% | — |
| CVE-2022-23551 | MED 5.3 | microsoft azure_ad_pod_identity aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request | 0.7% | — |
| CVE-2022-22031 | HIGH 7.8 | microsoft windows_10 Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2018-6664 | MED 5.8 | mcafee data_loss_prevention_endpoint Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility. | 0.7% | — |
| CVE-2026-60005 | HIGH 8.2 | f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause | 0.7% | — |
| CVE-2026-22153 | HIGH 8.1 | fortinet fortios An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is confi | 0.7% | — |
| CVE-2025-64663 | CRIT 9.9 | microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability | 0.7% | — |