IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-0844 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0808 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0631 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.8%
CVE-2019-15220 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver. 0.8%
CVE-2019-15211 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory. 0.8%
CVE-2015-5258 HIGH 8.8 fedoraproject fedora Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3. 0.8%
CVE-2010-4250 MED 4.9 linux linux_kernel Memory leak in the inotify_init1 function in fs/notify/inotify/inotify_user.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory consumption) via vectors involving failed attempts to create files. 0.8%
CVE-2005-4868 HIGH 7.1 ibm db2_universal_database Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service. 0.8%
CVE-2025-21363 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 0.8%
CVE-2024-28902 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-26255 MED 5.5 microsoft windows_10_1809 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-26207 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-20444 MED 5.5 cisco nexus_dashboard_fabric_controller A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. 0.8%
CVE-2023-36398 MED 6.5 microsoft windows_10_1507 Windows NTFS Information Disclosure Vulnerability 0.8%
CVE-2022-40732 MED 5.0 microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte 0.8%
CVE-2021-27853 MED 4.7 cisco catalyst_6503-e_firmware Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. 0.8%
CVE-2020-17137 HIGH 7.8 microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2018-9568 HIGH 7.8 canonical ubuntu_linux In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Version 0.8%
CVE-2008-0732 LOW 2.1 apache geronimo The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories. 0.8%
CVE-2026-65637 CRIT 9.8 apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrad 0.8%
CVE-2023-48362 HIGH 8.8 apache drill XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue. 0.8%
CVE-2023-36428 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability 0.8%
CVE-2023-36406 MED 5.5 microsoft windows_11_21h2 Windows Hyper-V Information Disclosure Vulnerability 0.8%
CVE-2023-28240 HIGH 8.8 microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability 0.8%
CVE-2022-37424 MED 6.5 opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. 0.8%