57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-11487 | HIGH 7.8 | canonical ubuntu_linux The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kern | 0.7% | — |
| CVE-2018-0165 | HIGH 7.4 | cisco ios_xe A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust buffers on an affected device, resulting in a denial of service (DoS) conditi | 0.7% | — |
| CVE-2017-12275 | HIGH 7.4 | cisco wireless_lan_controller_software A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a | 0.7% | — |
| CVE-2015-0735 | MED 6.8 | cisco unified_customer_voice_portal Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970. | 0.7% | — |
| CVE-2013-3472 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote attackers to hijack the authentication of arbitrary users for requests that make ELM modifications, aka Bug ID CS | 0.7% | — |
| CVE-2026-50686 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42895 | MED 6.5 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-42027 | CRIT 9.8 | apache opennlp Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully | 0.7% | — |
| CVE-2022-41085 | HIGH 7.5 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26797 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26794 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26790 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-47259 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports through two different NICs that belong to the same server. Olga w | 0.7% | — |
| CVE-2021-21096 | MED 5.5 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in | 0.7% | — |
| CVE-2020-5414 | MED 5.7 | vmware operations_manager VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Man | 0.7% | — |
| CVE-2020-12659 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation. | 0.7% | — |
| CVE-2018-20856 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled. | 0.7% | — |
| CVE-2018-0451 | HIGH 8.8 | cisco tetration_analytics A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due | 0.7% | — |
| CVE-2026-62899 | MED 5.9 | microsoft .net Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.7% | — |
| CVE-2026-59173 | HIGH 7.5 | apache traffic_server Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. | 0.7% | — |
| CVE-2026-43868 | MED 5.3 | apache thrift Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.7% | — |
| CVE-2026-33120 | HIGH 8.8 | microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-20821 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |