57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-67638 | HIGH 8.8 | microsoft sql_server_2025 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-67380 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-49097 | MED 6.5 | apache camel Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel IRC component. The camel-irc producer chooses the destination of an outgoing IRC message from the irc.s | 0.7% | — |
| CVE-2026-46195 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd | 0.7% | — |
| CVE-2025-24075 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-22218 | HIGH 8.5 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | 0.7% | — |
| CVE-2025-20224 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak | 0.7% | — |
| CVE-2024-43526 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43525 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26237 | HIGH 7.8 | microsoft windows_10_1809 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-40185 | MED 6.5 | shescape_project shescape shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections | 0.7% | — |
| CVE-2023-20042 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected | 0.7% | — |
| CVE-2023-20007 | MED 4.7 | cisco rv340_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code or cause the web-based management process on the | 0.7% | — |
| CVE-2020-3329 | MED 4.3 | cisco integrated_management_controller_supervisor A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affec | 0.7% | — |
| CVE-2014-0131 | LOW 2.9 | linux linux_kernel Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. | 0.7% | — |
| CVE-2025-30675 | MED 4.7 | apache cloudstack In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecu | 0.7% | — |
| CVE-2025-24063 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-29994 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-28901 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-28900 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-3389 | HIGH 7.8 | canonical ubuntu_linux A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac | 0.7% | — |
| CVE-2023-23421 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2018-10649 | MED 6.1 | citrix xenmobile_server There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. | 0.7% | — |
| CVE-2013-1212 | MED 5.8 | cisco nexus_1000v The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a craft | 0.7% | — |
| CVE-2025-58136 | HIGH 7.5 | apache traffic_server A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A wo | 0.7% | — |