IT
58.089 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.089 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-15213 MED 4.6 linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. 0.6%
CVE-2019-0026 MED 5.4 juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on adm 0.6%
CVE-2018-0415 MED 6.8 cisco wap121_firmware A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjace 0.6%
CVE-2014-8480 MED 4.9 linux linux_kernel The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer derefere 0.6%
CVE-2026-45455 LOW 3.3 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-34615 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject maliciou 0.6%
CVE-2025-27739 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27731 HIGH 7.8 microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27730 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27476 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27467 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27427 MED 4.3 apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo 0.6%
CVE-2025-26674 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2025-26666 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2024-50215 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after 0.6%
CVE-2024-40587 MED 6.7 fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or 0.6%
CVE-2024-38122 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0.6%
CVE-2024-38118 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0.6%
CVE-2022-49093 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: skbuff: fix coalescing for page_pool fragment recycling Fix a use-after-free when using page_pool with page fragments. We encountered this problem during normal RX in the hns3 driver: (1) I 0.6%
CVE-2022-23015 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processin 0.6%
CVE-2021-31354 HIGH 7.1 juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause 0.6%
CVE-2016-6427 HIGH 8.8 cisco unified_contact_center_express Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bu 0.6%
CVE-2016-6417 HIGH 8.8 cisco firesight_system_software Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. 0.6%
CVE-2026-67631 CRIT 9.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-29168 HIGH 7.3 apache http_server Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the 0.6%