57.925 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.925 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-24556 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulate | 0.8% | — |
| CVE-2019-12400 | MED 5.5 | apache santuario_xml_security_for_java In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread | 0.8% | — |
| CVE-2001-0316 | MED 4.6 | linux linux_kernel Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call. | 0.8% | — |
| CVE-2026-64609 | CRIT 9.1 | apache fory Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that d | 0.8% | — |
| CVE-2024-30102 | HIGH 7.3 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-48666 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still avai | 0.8% | — |
| CVE-2022-30135 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-47245 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut | 0.8% | — |
| CVE-2021-38662 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-1146 | MED 6.6 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially craf | 0.8% | — |
| CVE-2020-1130 | MED 6.6 | microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp | 0.8% | — |
| CVE-2019-7960 | HIGH 7.8 | adobe animate_cc Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. | 0.8% | — |
| CVE-2017-4926 | MED 5.4 | vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page. | 0.8% | — |
| CVE-2026-62902 | MED 6.5 | microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-57100 | CRIT 9.9 | microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-54998 | HIGH 8.8 | microsoft exchange_online Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50444 | HIGH 8.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50360 | HIGH 8.8 | microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-47647 | CRIT 9.9 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-45499 | CRIT 9.9 | microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32157 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-61623 | MED 6.5 | apache ofbiz Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. | 0.8% | — |
| CVE-2025-34193 | CRIT 9.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLaunche | 0.8% | — |
| CVE-2025-29815 | HIGH 7.6 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-21296 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Remote Code Execution Vulnerability | 0.8% | — |