57.925 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.925 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-47659 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: when a label 'foo' connects to a label 'bar' with tcp/ipv4, 'foo' always gets 'f | 0.8% | — |
| CVE-2024-29063 | HIGH 7.3 | microsoft azure_ai_search Azure AI Search Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-25734 | HIGH 8.1 | mozilla firefox After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resou | 0.8% | — |
| CVE-2023-21806 | HIGH 8.2 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 0.8% | — |
| CVE-2023-20100 | MED 6.8 | cisco ios_xe A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial | 0.8% | — |
| CVE-2020-1434 | MED 5.3 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, aka 'Windows Sync Host Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-11345 | MED 6.1 | citrix citrix_sd-wan_center Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. | 0.8% | — |
| CVE-2015-4259 | MED 4.3 | cisco unified_computing_system The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leve | 0.8% | — |
| CVE-2014-0049 | HIGH 7.4 | linux linux_kernel Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_wor | 0.8% | — |
| CVE-2011-4131 | MED 4.6 | linux linux_kernel The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words. | 0.8% | — |
| CVE-2025-59200 | HIGH 7.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. | 0.8% | — |
| CVE-2024-49766 | MED 5.3 | palletsprojects werkzeug Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially | 0.8% | — |
| CVE-2023-0575 | HIGH 7.2 | yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula | 0.8% | — |
| CVE-2022-43285 | HIGH 7.5 | f5 njs Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. | 0.8% | — |
| CVE-2022-35757 | HIGH 7.3 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30226 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-22022 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1702 | HIGH 7.8 | microsoft windows_10 Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1693 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1655 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1654 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1653 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1652 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1649 | HIGH 7.8 | microsoft windows_10 Active Template Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1646 | MED 6.6 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0.8% | — |