57.758 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.758 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-23238 | MED 6.5 | netapp storagegrid Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metric | 0.7% | — |
| CVE-2019-17180 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or u | 0.7% | — |
| CVE-2014-3405 | MED 4.8 | cisco ios_xe Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control Plane (ACP) and external Autonomic Networking Infrastructure (ANI) interfaces, which allows remote attackers to conduct route-injection atta | 0.7% | — |
| CVE-2025-30677 | MED 6.5 | apache pulsar Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This | 0.7% | — |
| CVE-2025-21312 | LOW 2.4 | microsoft windows_10_1507 Windows Smart Card Reader Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-43579 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43578 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38123 | MED 4.4 | microsoft windows_11_24h2 Windows Bluetooth Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-0882 | HIGH 8.8 | krontech single_connect Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. | 0.7% | — |
| CVE-2022-49670 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/ | 0.7% | — |
| CVE-2022-22229 | HIGH 8.4 | juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv | 0.7% | — |
| CVE-2020-26080 | MED 4.1 | cisco iot_field_network_director A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper d | 0.7% | — |
| CVE-2012-5723 | MED 6.1 | cisco asr_1001 Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948. | 0.7% | — |
| CVE-2026-78520 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33823 | CRIT 9.6 | microsoft teams Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-21235 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2026-20096 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi | 0.7% | — |
| CVE-2025-60728 | MED 4.3 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-53149 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-53226 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() ib_map_mr_sg() allows ULPs to specify NULL as the sg_offset argument. The driver needs to check whether it is a NULL pointer bef | 0.7% | — |
| CVE-2024-38155 | MED 5.5 | microsoft windows_10_1809 Security Center Broker Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-47104 | CRIT 9.8 | vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered s | 0.7% | — |
| CVE-2023-32018 | HIGH 7.8 | microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-32008 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29370 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |