58.070 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.070 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-38191 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->use | 1.2% | — |
| CVE-2025-21259 | MED 5.3 | microsoft outlook Microsoft Outlook Spoofing Vulnerability | 1.2% | — |
| CVE-2024-38089 | CRIT 9.1 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2023-30465 | MED 5.3 | apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the orderin | 1.2% | — |
| CVE-2023-28271 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-23269 | MED 5.4 | microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability | 1.2% | — |
| CVE-2021-40122 | MED 5.9 | cisco meeting_server A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An at | 1.2% | — |
| CVE-2021-26612 | HIGH 8.1 | tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | 1.2% | — |
| CVE-2020-27121 | MED 4.3 | cisco unified_communications_manager_im_and_presence_service A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial | 1.2% | — |
| CVE-2020-24003 | LOW 3.3 | microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli | 1.2% | — |
| CVE-2015-5156 | MED 6.1 | linux linux_kernel The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via | 1.2% | — |
| CVE-2015-4266 | MED 4.3 | cisco identity_services_engine_software The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a | 1.2% | — |
| CVE-2012-2852 | MED 6.8 | google chrome The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possi | 1.2% | — |
| CVE-2011-1874 | HIGH 7.8 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.2% | — |
| CVE-2025-61795 | MED 5.3 | apache tomcat Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but lef | 1.2% | — |
| CVE-2024-43574 | HIGH 8.3 | microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-28290 | MED 5.3 | microsoft remote_desktop_app Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-30175 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2021-26431 | HIGH 7.8 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-26097 | HIGH 8.8 | fortinet fortisandbox An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or | 1.2% | — |
| CVE-2020-29478 | HIGH 7.5 | broadcom ca_service_catalog CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition. | 1.2% | — |
| CVE-2020-1398 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu | 1.2% | — |
| CVE-2019-1065 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.2% | — |
| CVE-2018-5532 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by the cache even after the parent server revokes the record, if the DNS Cache is receiving a stream of requests | 1.2% | — |
| CVE-2017-11818 | MED 4.5 | microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level | 1.2% | — |