57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38616 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux | 0.7% | — |
| CVE-2024-38163 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-45188 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulner | 0.7% | — |
| CVE-2021-40470 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40466 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40443 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-15936 | LOW 2.6 | fortinet fortios A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets. | 0.7% | — |
| CVE-2019-8912 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. | 0.7% | — |
| CVE-2026-81376 | CRIT 9.6 | microsoft visual_studio_code Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.7% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-26035 | CRIT 9.8 | fortinet fortiweb An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthentica | 0.7% | — |
| CVE-2026-24209 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |
| CVE-2025-66200 | MED 5.4 | apache http_server mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: fro | 0.7% | — |
| CVE-2025-53804 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53803 | MED 5.5 | microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-30386 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-21402 | HIGH 7.8 | microsoft office Microsoft Office OneNote Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43883 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. | 0.7% | — |
| CVE-2024-43503 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26755 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there are spares that can be added or removed from conf, however, if reshape is still in progres | 0.7% | — |
| CVE-2024-26245 | HIGH 7.8 | microsoft windows_10_1507 Windows SMB Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35323 | HIGH 7.8 | microsoft windows_11_21h2 Windows OLE Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35313 | HIGH 7.8 | microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23377 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-30611 | MED 5.4 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject | 0.7% | — |