57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-47179 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff4234f changes _pnfs_return_layout() to call pnfs_mark_matching_lsegs_return() passing NULL as the str | 0.7% | — |
| CVE-2021-1566 | HIGH 7.4 | cisco asyncos A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic betwe | 0.7% | — |
| CVE-2020-3997 | MED 5.4 | vmware horizon VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed. | 0.7% | — |
| CVE-2018-7755 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use | 0.7% | — |
| CVE-2018-10840 | MED 6.6 | canonical ubuntu_linux Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image. | 0.7% | — |
| CVE-2026-70329 | HIGH 8.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-65098 | HIGH 8.1 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | 0.7% | — |
| CVE-2026-47298 | HIGH 8.0 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-20946 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-24988 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.7% | — |
| CVE-2025-24987 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.7% | — |
| CVE-2025-21284 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-21280 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-43524 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43523 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-30092 | HIGH 8.0 | microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-20155 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker wit | 0.7% | — |
| CVE-2022-21914 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21885 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21884 | HIGH 7.8 | microsoft windows_server Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21835 | HIGH 7.8 | microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-67370 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-62817 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2026-42527 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' | 0.7% | — |
| CVE-2026-24266 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |