58.089 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.089 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15213 | MED 4.6 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. | 0.6% | — |
| CVE-2019-0026 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on adm | 0.6% | — |
| CVE-2018-0415 | MED 6.8 | cisco wap121_firmware A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjace | 0.6% | — |
| CVE-2014-8480 | MED 4.9 | linux linux_kernel The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer derefere | 0.6% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-34615 | CRIT 9.3 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject maliciou | 0.6% | — |
| CVE-2025-27739 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27731 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27730 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27476 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27467 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27427 | MED 4.3 | apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo | 0.6% | — |
| CVE-2025-26674 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-26666 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-50215 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after | 0.6% | — |
| CVE-2024-40587 | MED 6.7 | fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or | 0.6% | — |
| CVE-2024-38122 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38118 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-49093 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: skbuff: fix coalescing for page_pool fragment recycling Fix a use-after-free when using page_pool with page fragments. We encountered this problem during normal RX in the hns3 driver: (1) I | 0.6% | — |
| CVE-2022-23015 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processin | 0.6% | — |
| CVE-2021-31354 | HIGH 7.1 | juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause | 0.6% | — |
| CVE-2016-6427 | HIGH 8.8 | cisco unified_contact_center_express Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bu | 0.6% | — |
| CVE-2016-6417 | HIGH 8.8 | cisco firesight_system_software Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. | 0.6% | — |
| CVE-2026-67631 | CRIT 9.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-29168 | HIGH 7.3 | apache http_server Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the | 0.6% | — |