57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-47956 | MED 5.5 | microsoft windows_security_app External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | 0.7% | — |
| CVE-2025-27091 | HIGH 7.5 | cisco openh264 OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulnerability is due to a r | 0.7% | — |
| CVE-2024-38047 | HIGH 7.8 | microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36551 | MED 4.3 | fortinet fortisiem A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. | 0.7% | — |
| CVE-2023-33171 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-28314 | MED 6.1 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-21753 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-49280 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underflow in nfssvc_decode_writeargs() Smatch complains: fs/nfsd/nfsxdr.c:341 nfssvc_decode_writeargs() warn: no lower bound on 'args->len' Change the type to unsigned to p | 0.7% | — |
| CVE-2022-35706 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0.7% | — |
| CVE-2022-21867 | HIGH 7.0 | microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21863 | HIGH 7.0 | microsoft windows_10 Windows StateRepository API Server file Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16983 | MED 5.7 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0.7% | — |
| CVE-2014-7970 | MED 5.5 | canonical ubuntu_linux The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both argumen | 0.7% | — |
| CVE-2011-0562 | MED 6.9 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than | 0.7% | — |
| CVE-2009-1914 | MED 4.9 | linux linux_kernel The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers | 0.7% | — |
| CVE-2025-62220 | HIGH 8.8 | microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-21346 | HIGH 7.1 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-41073 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear the RQF_SPEC | 0.7% | — |
| CVE-2024-1552 | HIGH 7.5 | debian debian_linux Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | 0.7% | — |
| CVE-2024-0136 | HIGH 7.6 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit i | 0.7% | — |
| CVE-2023-39176 | MED 5.8 | linux linux_kernel A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacke | 0.7% | — |
| CVE-2023-38041 | HIGH 7.0 | ivanti secure_access_client A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | 0.7% | — |
| CVE-2023-34058 | HIGH 7.1 | debian debian_linux VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target vi | 0.7% | — |
| CVE-2020-36516 | MED 5.9 | linux linux_kernel An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session. | 0.7% | — |
| CVE-2017-7518 | MED 5.5 | canonical ubuntu_linux A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process insi | 0.7% | — |