58.251 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.251 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42319 | MED 4.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-6692 | HIGH 7.8 | fortinet forticlient A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL. | 0.6% | — |
| CVE-2018-14889 | HIGH 7.8 | apache couchdb CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. | 0.6% | — |
| CVE-2017-18549 | MED 5.5 | linux linux_kernel An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure. | 0.6% | — |
| CVE-2015-10010 | LOW 3.1 | cisco openresolve A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched | 0.6% | — |
| CVE-2004-1072 | HIGH 7.2 | linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow | 0.6% | — |
| CVE-2026-78442 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69414 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | 0.6% | — |
| CVE-2026-67593 | CRIT 9.1 | apache artemis A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2. | 0.6% | — |
| CVE-2026-62706 | HIGH 8.8 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-40542 | HIGH 7.3 | apache httpclient Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes thi | 0.6% | — |
| CVE-2026-33006 | MED 4.8 | apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 0.6% | — |
| CVE-2025-53192 | HIGH 8.8 | apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue, the OGNL engine parses and evaluates the | 0.6% | — |
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0.6% | — |
| CVE-2024-6222 | HIGH 7.0 | docker desktop In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/ | 0.6% | — |
| CVE-2023-52885 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r | 0.6% | — |
| CVE-2023-3864 | HIGH 7.2 | snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 0.6% | — |
| CVE-2023-29333 | LOW 3.3 | microsoft 365_apps Microsoft Access Denial of Service Vulnerability | 0.6% | — |
| CVE-2023-26078 | HIGH 7.8 | atera atera Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. | 0.6% | — |
| CVE-2023-24594 | MED 5.3 | f5 big-ip_access_policy_manager When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.6% | — |
| CVE-2022-38436 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 0.6% | — |
| CVE-2022-36077 | HIGH 7.2 | electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, | 0.6% | — |
| CVE-2022-35820 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-43240 | HIGH 7.8 | microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-43230 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0.6% | — |