IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-59200 HIGH 7.7 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. 0.8%
CVE-2024-49766 MED 5.3 palletsprojects werkzeug Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially 0.8%
CVE-2023-0575 HIGH 7.2 yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula 0.8%
CVE-2022-43285 HIGH 7.5 f5 njs Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. 0.8%
CVE-2022-35757 HIGH 7.3 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.8%
CVE-2022-30226 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2022-22022 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2021-1702 HIGH 7.8 microsoft windows_10 Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability 0.8%
CVE-2021-1693 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1655 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1654 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1653 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1652 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1649 HIGH 7.8 microsoft windows_10 Active Template Library Elevation of Privilege Vulnerability 0.8%
CVE-2021-1646 MED 6.6 microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability 0.8%
CVE-2020-24556 HIGH 7.8 trendmicro apex_one A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulate 0.8%
CVE-2019-12400 MED 5.5 apache santuario_xml_security_for_java In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread 0.8%
CVE-2001-0316 MED 4.6 linux linux_kernel Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call. 0.8%
CVE-2025-49753 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49673 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49669 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49668 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49663 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2024-47659 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: when a label 'foo' connects to a label 'bar' with tcp/ipv4, 'foo' always gets 'f 0.8%
CVE-2024-29063 HIGH 7.3 microsoft azure_ai_search Azure AI Search Information Disclosure Vulnerability 0.8%