58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-5766 | CRIT 9.8 | devolutions remote_desktop_manager A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet. | 0.6% | — |
| CVE-2023-41267 | HIGH 7.8 | apache airflow_hdfs_provider In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed wh | 0.6% | — |
| CVE-2022-42722 | MED 5.5 | debian debian_linux In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices. | 0.6% | — |
| CVE-2022-38003 | HIGH 7.8 | microsoft windows_10 Windows Resilient File System Elevation of Privilege | 0.6% | — |
| CVE-2022-37980 | HIGH 7.8 | microsoft windows_10 Windows DHCP Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-19160 | MED 5.7 | cabsoftware reportexpress_proplus Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). | 0.6% | — |
| CVE-2019-16232 | MED 4.1 | canonical ubuntu_linux drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. | 0.6% | — |
| CVE-2018-7740 | MED 5.5 | canonical ubuntu_linux The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call. | 0.6% | — |
| CVE-2018-15395 | MED 5.4 | cisco wireless_lan_controller_software A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this acce | 0.6% | — |
| CVE-2015-7359 | HIGH 7.8 | ciphershed ciphershed The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impers | 0.6% | — |
| CVE-2014-8133 | LOW 2.1 | linux linux_kernel arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, vi | 0.6% | — |
| CVE-2012-2136 | HIGH 7.2 | linux linux_kernel The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privil | 0.6% | — |
| CVE-2025-33062 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33055 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-45772 | MED 5.1 | apache lucene_replicator Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator | 0.6% | — |
| CVE-2024-31156 | HIGH 8.0 | f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Te | 0.6% | — |
| CVE-2024-29052 | HIGH 7.8 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-44182 | HIGH 7.3 | juniper junos An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes | 0.6% | — |
| CVE-2022-28356 | MED 5.5 | debian debian_linux In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c. | 0.6% | — |
| CVE-2022-21866 | HIGH 7.0 | microsoft windows_10 Windows System Launcher Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-20861 | CRIT 9.8 | cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit | 0.6% | — |
| CVE-2022-20772 | MED 4.7 | cisco email_security_appliance_firmware A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its e | 0.6% | — |
| CVE-2021-40477 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34793 | HIGH 8.6 | cisco adaptive_security_appliance A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a den | 0.6% | — |
| CVE-2019-12573 | HIGH 7.1 | londontrustmedia private_internet_access_vpn_client A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log opt | 0.6% | — |