57.872 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.872 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21187 | HIGH 7.8 | microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-21179 | MED 4.8 | microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-43505 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-36031 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem fo | 0.7% | — |
| CVE-2021-47274 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542 | 0.7% | — |
| CVE-2021-20432 | MED 6.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Fo | 0.7% | — |
| CVE-2020-5740 | HIGH 7.8 | plex media_server Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges. | 0.7% | — |
| CVE-2018-15372 | HIGH 8.1 | cisco ios_xe A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic thr | 0.7% | — |
| CVE-2016-9774 | HIGH 7.8 | apache tomcat The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, | 0.7% | — |
| CVE-2015-2337 | MED 5.8 | vmware fusion TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, w | 0.7% | — |
| CVE-2015-2336 | MED 5.8 | vmware fusion TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, | 0.7% | — |
| CVE-2026-64320 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64 | 0.7% | — |
| CVE-2026-42833 | CRIT 9.1 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-49715 | HIGH 7.5 | microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-49674 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2024-41742 | HIGH 7.5 | ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial | 0.7% | — |
| CVE-2024-38605 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card o | 0.7% | — |
| CVE-2024-37984 | HIGH 8.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-30359 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability | 0.7% | — |
| CVE-2024-30349 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerab | 0.7% | — |
| CVE-2024-29989 | HIGH 8.4 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26828 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, th | 0.7% | — |
| CVE-2023-28309 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2021-1522 | MED 4.3 | cisco connected_mobile_experiences A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on | 0.7% | — |
| CVE-2020-8144 | HIGH 8.4 | ui unifi_video The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It ac | 0.7% | — |