57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1447 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445. | 0.8% | — |
| CVE-2019-1445 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447. | 0.8% | — |
| CVE-2019-12881 | HIGH 7.8 | linux linux_kernel i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl ca | 0.8% | — |
| CVE-2026-64608 | CRIT 9.8 | apache fory Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent s | 0.8% | — |
| CVE-2026-21523 | HIGH 8.0 | microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-25069 | MED 6.5 | apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi | 0.8% | — |
| CVE-2024-43542 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43540 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43538 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43537 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2023-21749 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-41043 | LOW 3.3 | microsoft office Microsoft Office Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-33631 | HIGH 7.3 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-29473 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminat | 0.8% | — |
| CVE-2022-28706 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En | 0.8% | — |
| CVE-2022-26517 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, undisclosed requests can | 0.8% | — |
| CVE-2022-26370 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message | 0.8% | — |
| CVE-2021-28309 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-27093 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-26417 | MED 5.5 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-3267 | HIGH 7.1 | cisco unified_contact_center_express A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an aff | 0.8% | — |
| CVE-2020-16922 | MED 5.3 | microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by | 0.8% | — |
| CVE-2013-6698 | MED 4.3 | cisco wireless_lan_controller The web interface on Cisco Wireless LAN Controller (WLC) devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "c | 0.8% | — |
| CVE-2026-8481 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() | 0.8% | — |
| CVE-2026-69372 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. | 0.8% | — |