57.954 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.954 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-5495 | HIGH 8.8 | fedoraproject fedora Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.8% | — |
| CVE-2023-21817 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-41741 | HIGH 7.0 | debian debian_linux NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to co | 0.8% | — |
| CVE-2022-22939 | MED 4.9 | vmware cloud_foundation VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view c | 0.8% | — |
| CVE-2020-0806 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0772. | 0.8% | — |
| CVE-2013-5527 | MED 5.7 | cisco ios The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030. | 0.8% | — |
| CVE-2011-1082 | MED 4.9 | linux linux_kernel fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory | 0.8% | — |
| CVE-2026-71257 | HIGH 7.5 | apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f | 0.8% | — |
| CVE-2026-69724 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-67260 | HIGH 7.3 | apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug | 0.8% | — |
| CVE-2026-65927 | HIGH 7.5 | apache tomcat Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1. | 0.8% | — |
| CVE-2024-56180 | CRIT 9.8 | apache eventmesh CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian | 0.8% | — |
| CVE-2024-24773 | MED 4.9 | apache superset Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which | 0.8% | — |
| CVE-2022-24513 | HIGH 7.8 | microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0912 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run | 0.8% | — |
| CVE-2019-7962 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. | 0.8% | — |
| CVE-2016-9194 | MED 6.5 | cisco wireless_lan_controller A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to i | 0.8% | — |
| CVE-2016-1238 | HIGH 7.8 | apache spamassassin (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/b | 0.8% | — |
| CVE-2013-6014 | CRIT 9.3 | juniper junos Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is | 0.8% | — |
| CVE-2025-66168 | MED 5.4 | apache activemq WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt https://www.cve.org/CVERecord? | 0.8% | — |
| CVE-2025-50168 | HIGH 7.8 | microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2024-54021 | MED 6.5 | fortinet fortios An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via c | 0.8% | — |
| CVE-2024-38170 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-30068 | HIGH 8.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-27525 | LOW 3.1 | apache superset An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 | 0.8% | — |