58.140 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.140 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-59258 | MED 6.2 | microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-49729 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-27728 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27490 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24074 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24073 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24062 | HIGH 7.8 | microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24060 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24058 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-38016 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-41083 | HIGH 7.8 | microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37999 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37994 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37993 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-41032 | MED 6.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us | 0.6% | — |
| CVE-2021-26608 | HIGH 8.8 | handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | 0.6% | — |
| CVE-2020-3968 | HIGH 8.2 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xH | 0.6% | — |
| CVE-2020-36115 | MED 5.4 | egavilanmedia phpcrud Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'. | 0.6% | — |
| CVE-2014-3610 | MED 5.5 | canonical ubuntu_linux The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by | 0.6% | — |
| CVE-2014-3404 | MED 4.3 | cisco ios_xe The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677. | 0.6% | — |
| CVE-2013-4312 | MED 6.2 | linux linux_kernel The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. | 0.6% | — |
| CVE-2012-4088 | MED 4.3 | cisco unified_computing_system The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769. | 0.6% | — |
| CVE-2026-78526 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-78521 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-78517 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |