58.140 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.140 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-78514 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-78507 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-78504 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-77901 | HIGH 8.8 | microsoft 365_apps Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69366 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-68846 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-29169 | HIGH 7.5 | apache http_server A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was m | 0.6% | — |
| CVE-2025-66675 | HIGH 8.2 | apache struts Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1 | 0.6% | — |
| CVE-2025-21748 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add bounds checking using KS | 0.6% | — |
| CVE-2023-35355 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-44710 | HIGH 7.8 | microsoft windows_11 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-22227 | MED 5.3 | juniper junos_os_evolved An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated network-based attacker to cause a partial Denial of Service (DoS). On r | 0.6% | — |
| CVE-2021-47536 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix wrong list_del in smc_lgr_cleanup_early smc_lgr_cleanup_early() meant to delete the link group from the link group list, but it deleted the list head by mistake. This may cause | 0.6% | — |
| CVE-2021-46911 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. It's better to take tx_ctx lock for the complete skb transmit, to avoid page cleanup if ACK rec | 0.6% | — |
| CVE-2021-34789 | MED 4.8 | cisco tetration A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected system. This vulnerability exists because the web-based management inter | 0.6% | — |
| CVE-2021-34759 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. | 0.6% | — |
| CVE-2021-34731 | MED 4.8 | cisco prime_access_registrar A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability exists because the web-based managemen | 0.6% | — |
| CVE-2021-24092 | HIGH 7.8 | microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-1607 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the w | 0.6% | — |
| CVE-2021-1606 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the w | 0.6% | — |
| CVE-2021-1605 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the w | 0.6% | — |
| CVE-2021-1604 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the w | 0.6% | — |
| CVE-2021-1603 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the w | 0.6% | — |
| CVE-2020-6641 | MED 4.3 | fortinet fortipresence Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters. | 0.6% | — |
| CVE-2020-26066 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External | 0.6% | — |