58.444 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.444 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-45649 | HIGH 7.1 | microsoft excel Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | 0.4% | — |
| CVE-2026-41091 | HIGH 7.8 | microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 0.4% | |
| CVE-2026-21251 | HIGH 7.8 | microsoft windows_server_2016 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21246 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21245 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21239 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21236 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21232 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20956 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-55321 | CRIT 9.3 | microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2025-43595 | HIGH 7.8 | msp360 backup An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22). | 0.4% | — |
| CVE-2025-4232 | HIGH 8.8 | paloaltonetworks globalprotect An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root. | 0.4% | — |
| CVE-2025-20315 | HIGH 8.6 | cisco ios_xe A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition. This vulnerability is du | 0.4% | — |
| CVE-2024-52982 | HIGH 7.8 | adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2024-46799 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX If number of TX queues are set to 1 we get a NULL pointer dereference during XDP_TX. ~# ethtool -L eth0 tx 1 ~# ./xdp-trafficgen | 0.4% | — |
| CVE-2024-46796 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_set_path_size() If smb2_compound_op() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() before retryi | 0.4% | — |
| CVE-2024-28889 | MED 5.9 | f5 big-ip_access_policy_manager When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi | 0.4% | — |
| CVE-2024-23670 | HIGH 7.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.4% | — |
| CVE-2024-23667 | HIGH 7.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.4% | — |
| CVE-2024-20517 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.4% | — |
| CVE-2024-20516 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.4% | — |
| CVE-2024-20408 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. | 0.4% | — |
| CVE-2023-22657 | HIGH 7.0 | f5 f5os-a On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not e | 0.4% | — |
| CVE-2022-49743 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ovl: Use "buf" flexible array for memcpy() destination The "buf" flexible array needs to be the memcpy() destination to avoid false positive run-time warning from the recent FORTIFY_SOURCE h | 0.4% | — |
| CVE-2022-45862 | LOW 3.7 | fortinet fortios An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versi | 0.4% | — |