IT
58.202 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.202 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-38150 HIGH 7.8 microsoft windows_11_21h2 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2023-21739 HIGH 7.0 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0.6%
CVE-2022-38457 MED 6.3 linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the 0.6%
CVE-2022-20765 MED 4.8 cisco ucs_director A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vuln 0.6%
CVE-2021-39016 MED 4.3 ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed for t 0.6%
CVE-2021-34511 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.6%
CVE-2021-34488 HIGH 7.8 microsoft windows_10 Windows Console Driver Elevation of Privilege Vulnerability 0.6%
CVE-2021-34477 HIGH 7.8 microsoft .net_education_bundle_sdk_install_tool Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability 0.6%
CVE-2021-34460 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.6%
CVE-2021-1218 MED 5.4 cisco smart_software_manager_on-prem A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in 0.6%
CVE-2020-5025 HIGH 7.8 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root 0.6%
CVE-2020-3314 MED 6.1 cisco advanced_malware_protection_for_endpoints A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP 0.6%
CVE-2018-19824 HIGH 7.8 canonical ubuntu_linux In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c. 0.6%
CVE-2018-0306 HIGH 7.8 cisco nx-os A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker coul 0.6%
CVE-2015-8953 MED 5.5 linux linux_kernel fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer. 0.6%
CVE-2005-0124 LOW 2.1 linux linux_kernel The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a 0.6%
CVE-2002-1233 LOW 2.6 apache http_server A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on tempora 0.6%
CVE-2026-76986 MED 6.1 apache wicket Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — 0.6%
CVE-2026-69416 MED 5.7 microsoft windows_10_1607 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. 0.6%
CVE-2026-69405 MED 5.7 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. 0.6%
CVE-2026-54475 HIGH 7.5 apache activemq Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only ch 0.6%
CVE-2026-50528 HIGH 8.2 microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.6%
CVE-2026-50481 CRIT 9.9 microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-43037 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as str 0.6%
CVE-2026-26149 CRIT 9.0 microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. 0.6%