IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-30532 MED 5.3 octopus octopus_server In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. 0.5% —
CVE-2022-28875 MED 4.3 f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker. 0.5% —
CVE-2021-31193 HIGH 7.8 microsoft windows_10 Windows SSDP Service Elevation of Privilege Vulnerability 0.5% —
CVE-2021-29683 MED 6.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. 0.5% —
CVE-2019-15924 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure. 0.5% —
CVE-2018-0381 MED 6.8 cisco aironet_access_points A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadloc 0.5% —
CVE-2015-8970 MED 5.5 linux linux_kernel crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference a 0.5% —
CVE-2013-4163 MED 4.7 linux linux_kernel The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a 0.5% —
CVE-2008-1932 MED 6.8 realtek hd_audio_codec_drivers Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request. 0.5% —
CVE-2026-69314 HIGH 7.1 microsoft windows_10_1607 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-65816 CRIT 10.0 microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-52957 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. When decoding this CRUSH map in crush_d 0.5% —
CVE-2026-52954 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally 0.5% —
CVE-2026-43230 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/rds: Clear reconnect pending bit When canceling the reconnect worker, care must be taken to reset the reconnect-pending bit. If the reconnect worker has not yet been scheduled before it 0.5% —
CVE-2026-43226 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_ 0.5% —
CVE-2026-32208 HIGH 8.8 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. 0.5% —
CVE-2026-29170 MED 6.1 apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v 0.5% —
CVE-2026-23456 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checkin 0.5% —
CVE-2026-20944 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-64677 HIGH 8.2 microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. 0.5% —
CVE-2025-21405 HIGH 7.3 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.5% —
CVE-2024-45009 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == 0) ... before decrementing the add_addr_accepted counte 0.5% —
CVE-2023-21815 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.5% —
CVE-2022-41054 HIGH 7.8 microsoft windows_10 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.5% —
CVE-2022-35707 HIGH 7.8 adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0.5% —