IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-15793 MED 6.5 canonical ubuntu_linux In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, wher 0.7%
CVE-2018-6234 MED 5.5 trendmicro antivirus\+ An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnci 0.7%
CVE-2009-0471 MED 6.8 cisco ios Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request. 0.7%
CVE-2026-68819 MED 5.9 microsoft windows_10_1607 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. 0.7%
CVE-2026-66301 MED 6.5 microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-60080 HIGH 7.3 apache fory Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommen 0.7%
CVE-2026-48142 MED 4.8 f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, u 0.7%
CVE-2026-33557 CRIT 9.1 apache kafka A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without valida 0.7%
CVE-2026-29220 MED 6.5 apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.7%
CVE-2025-24084 HIGH 8.4 microsoft windows_11_22h2 Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. 0.7%
CVE-2024-43636 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0.7%
CVE-2024-22267 CRIT 9.3 vmware fusion VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on th 0.7%
CVE-2023-52669 HIGH 8.2 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this 0.7%
CVE-2023-21569 MED 5.5 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 0.7%
CVE-2022-26938 HIGH 7.0 microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability 0.7%
CVE-2021-47307 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses- 0.7%
CVE-2021-47267 MED 6.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [i 0.7%
CVE-2021-47109 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will 0.7%
CVE-2021-42274 MED 6.8 microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability 0.7%
CVE-2021-31951 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2021-1690 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7%
CVE-2021-1689 HIGH 7.8 microsoft windows_10 Windows Multipoint Management Elevation of Privilege Vulnerability 0.7%
CVE-2021-1688 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.7%
CVE-2021-1687 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7%
CVE-2021-1686 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7%