58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-77103 | HIGH 7.5 | commvault commvault CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.5% | — |
| CVE-2026-69777 | HIGH 8.0 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network. | 0.5% | — |
| CVE-2026-65675 | HIGH 7.1 | microsoft github_copilot_chat No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-47296 | HIGH 7.5 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-42404 | MED 6.5 | apache neethi Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitra | 0.5% | — |
| CVE-2026-35429 | MED 4.3 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-3538 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-35086 | MED 6.5 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2025-49667 | HIGH 7.8 | microsoft windows_10_1507 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-52052 | HIGH 7.2 | wowza streaming_engine Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. | 0.5% | — |
| CVE-2024-43530 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-38093 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-38083 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-38082 | MED 4.7 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-22389 | HIGH 7.2 | f5 big-ip_access_policy_manager When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-21397 | MED 5.3 | microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-47131 | HIGH 7.5 | n-able passportal The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. | 0.5% | — |
| CVE-2023-32017 | HIGH 7.8 | microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2023-24862 | MED 5.5 | microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability | 0.5% | — |
| CVE-2023-22663 | MED 5.9 | intel unison_software Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0.5% | — |
| CVE-2023-21697 | MED 6.2 | microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-38408 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac | 0.5% | — |
| CVE-2022-35758 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-0617 | MED 5.5 | debian debian_linux A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc | 0.5% | — |
| CVE-2021-29755 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015. | 0.5% | — |