58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20243 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20217 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imp | 0.6% | — |
| CVE-2026-20216 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An | 0.6% | — |
| CVE-2026-20215 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imprope | 0.6% | — |
| CVE-2026-20214 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20213 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imprope | 0.6% | — |
| CVE-2025-58724 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-47980 | MED 6.2 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-26681 | MED 6.7 | microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-23303 | HIGH 7.8 | nvidia nemo NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0.6% | — |
| CVE-2024-43450 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.6% | — |
| CVE-2024-26641 | HIGH 8.6 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h var | 0.6% | — |
| CVE-2024-26362 | HIGH 8.8 | enpass password_manager HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note. | 0.6% | — |
| CVE-2023-27863 | MED 4.4 | ibm spectrum_protect IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325. | 0.6% | — |
| CVE-2023-23778 | MED 4.9 | fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests. | 0.6% | — |
| CVE-2023-20131 | MED 6.5 | cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-s | 0.6% | — |
| CVE-2022-41336 | MED 6.8 | fortinet fortiportal An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross s | 0.6% | — |
| CVE-2022-38434 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.6% | — |
| CVE-2020-24562 | HIGH 7.8 | trendmicro officescan A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ab | 0.6% | — |
| CVE-2019-5694 | MED 6.5 | nvidia gpu_driver NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), whic | 0.6% | — |
| CVE-2019-19480 | MED 4.6 | opensc_project opensc An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry. | 0.6% | — |
| CVE-2012-6026 | MED 6.1 | cisco aironet_access_point_software The HTTP Profiler on the Cisco Aironet Access Point with software 15.2 and earlier does not properly manage buffers, which allows remote attackers to cause a denial of service (device reload) via crafted HTTP requests, aka Bug ID CSCuc62460. | 0.6% | — |
| CVE-2026-85880 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | 0.6% | |
| CVE-2026-8505 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuratio | 0.6% | — |
| CVE-2026-73016 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 0.6% | — |