IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-43239 HIGH 7.1 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 0.5% —
CVE-2021-42312 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 0.5% —
CVE-2021-36968 HIGH 7.8 microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability 0.5% —
CVE-2021-23018 HIGH 7.4 f5 nginx_controller Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster. 0.5% —
CVE-2020-15935 MED 4.3 fortinet fortiadc A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating th 0.5% —
CVE-2017-7218 HIGH 7.8 paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters. 0.5% —
CVE-2016-9221 MED 4.3 cisco aironet_access_point_software A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This v 0.5% —
CVE-2015-8816 MED 6.8 linux linux_kernel The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or 0.5% —
CVE-2026-66302 CRIT 9.8 microsoft skype_for_business_server External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-62820 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-53399 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_statei 0.5% —
CVE-2026-53398 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfse 0.5% —
CVE-2026-26113 HIGH 8.4 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-47953 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-36128 HIGH 7.5 ibm mq IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a 0.5% —
CVE-2024-46665 LOW 3.7 fortinet fortios An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests 0.5% —
CVE-2024-21596 MED 5.3 juniper junos A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). If an attacker sends a specific BGP UPDATE 0.5% —
CVE-2024-20745 HIGH 7.8 adobe premiere_pro Premiere Pro versions 24.1, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu 0.5% —
CVE-2023-38175 HIGH 7.8 microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability 0.5% —
CVE-2023-35364 HIGH 8.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0.5% —
CVE-2023-28299 MED 5.5 microsoft visual_studio_2017 Visual Studio Spoofing Vulnerability 0.5% —
CVE-2022-23276 HIGH 7.8 microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability 0.5% —
CVE-2022-1652 HIGH 7.8 debian debian_linux Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbit 0.5% —
CVE-2021-40467 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.5% —
CVE-2021-36134 HIGH 7.4 netop vision_pro Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). 0.5% —