57.758 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.758 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-53199 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_buf() copies page buffer entries into the VMBus send buffer using phys_to_virt() on the entry PFN. Entries for t | 0.7% | — |
| CVE-2026-52929 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt. That leaves removed stream metadata behind, | 0.7% | — |
| CVE-2026-41106 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-59503 | CRIT 10.0 | microsoft azure_compute_resource_provider Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-43556 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-20194 | MED 4.9 | cisco identity_services_engine A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privilege | 0.7% | — |
| CVE-2022-26899 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-43877 | HIGH 8.8 | microsoft asp.net_core ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1158 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0.7% | — |
| CVE-2021-1151 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0.7% | — |
| CVE-2020-3460 | MED 6.1 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because t | 0.7% | — |
| CVE-2019-1952 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is | 0.7% | — |
| CVE-2017-0331 | HIGH 7.8 | google android An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 0.7% | — |
| CVE-2015-0710 | MED 6.1 | cisco ios_xe The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs | 0.7% | — |
| CVE-2013-7421 | LOW 2.1 | canonical ubuntu_linux The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644. | 0.7% | — |
| CVE-2010-2240 | HIGH 7.2 | linux linux_kernel The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to | 0.7% | — |
| CVE-2001-0317 | LOW 3.7 | linux linux_kernel Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process. | 0.7% | — |
| CVE-2026-20129 | CRIT 9.8 | cisco catalyst_sd-wan_manager A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authenticatio | 0.7% | — |
| CVE-2024-38256 | MED 5.5 | microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-38235 | MED 6.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-36504 | MED 6.5 | fortinet fortios An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web p | 0.7% | — |
| CVE-2023-4595 | HIGH 7.5 | seattlelab slmail An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of | 0.7% | — |
| CVE-2023-20107 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and AS | 0.7% | — |
| CVE-2022-39946 | HIGH 7.6 | fortinet fortinac An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative int | 0.7% | — |
| CVE-2022-26932 | HIGH 8.2 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |