58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-0056 | MED 6.8 | cisco ironport_encryption_appliance Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before | 0.5% | — |
| CVE-2026-67305 | HIGH 8.8 | freerdp freerdp FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP | 0.5% | — |
| CVE-2026-62900 | MED 5.9 | microsoft .net Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-53733 | HIGH 8.4 | microsoft 365_apps Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-49216 | CRIT 9.8 | trendmicro trend_micro_endpoint_encryption An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | 0.5% | — |
| CVE-2024-53138 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e | 0.5% | — |
| CVE-2024-43644 | HIGH 7.8 | microsoft windows_10_1507 Windows Client-Side Caching Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-26583 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past th | 0.5% | — |
| CVE-2024-20278 | MED 6.5 | cisco ios_xe A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exp | 0.5% | — |
| CVE-2024-1221 | LOW 3.1 | papercut papercut_mf This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affec | 0.5% | — |
| CVE-2023-32052 | MED 5.4 | microsoft power_apps Microsoft Power Apps (online) Spoofing Vulnerability | 0.5% | — |
| CVE-2023-20271 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability i | 0.5% | — |
| CVE-2022-41780 | MED 5.5 | f5 f5os-a In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. | 0.5% | — |
| CVE-2022-23442 | MED 4.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs | 0.5% | — |
| CVE-2021-42285 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-24102 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-0253 | HIGH 7.8 | juniper junos NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affects Juniper Networks Ju | 0.5% | — |
| CVE-2016-3138 | MED 4.6 | canonical ubuntu_linux The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint de | 0.5% | — |
| CVE-2016-3137 | MED 4.6 | canonical ubuntu_linux drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descript | 0.5% | — |
| CVE-2014-7283 | MED 4.9 | linux linux_kernel The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) | 0.5% | — |
| CVE-2004-2515 | HIGH 7.2 | vmware workstation Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or | 0.5% | — |
| CVE-2026-79048 | HIGH 8.8 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-78989 | CRIT 9.6 | google chrome Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-77907 | HIGH 8.8 | microsoft visual_studio_2026 Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-77486 | HIGH 8.8 | microsoft sql_server_2017 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. | 0.5% | — |