57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-27853 | MED 4.7 | cisco catalyst_6503-e_firmware Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | 0.8% | — |
| CVE-2020-17137 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2018-9568 | HIGH 7.8 | canonical ubuntu_linux In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Version | 0.8% | — |
| CVE-2008-0732 | LOW 2.1 | apache geronimo The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories. | 0.8% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0.8% | — |
| CVE-2026-47655 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-20934 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20848 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-24039 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38119 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38057 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38034 | HIGH 7.8 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-24749 | HIGH 7.5 | geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi | 0.8% | — |
| CVE-2023-34395 | HIGH 7.8 | apache apache-airflow-providers-odbc Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver pa | 0.8% | — |
| CVE-2023-33162 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-31772 | MED 5.3 | ibm mq IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335. | 0.8% | — |
| CVE-2022-2778 | CRIT 9.8 | octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 0.8% | — |
| CVE-2022-25990 | MED 5.3 | f5 f5os-a On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.8% | — |
| CVE-2021-1727 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0868 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0867. | 0.8% | — |
| CVE-2020-0867 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0868. | 0.8% | — |
| CVE-2020-0857 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0844 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0808 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0631 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |