IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-61958 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit 0.4% —
CVE-2025-49686 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-27200 HIGH 7.8 adobe animate Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali 0.4% —
CVE-2025-20210 HIGH 7.3 cisco catalyst_center A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication 0.4% —
CVE-2024-35998 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb3: fix lock ordering potential deadlock in cifs_sync_mid_result Coverity spotted that the cifs_sync_mid_result function could deadlock "Thread deadlock (ORDER_REVERSAL) lock_order: Calli 0.4% —
CVE-2024-20764 MED 5.5 adobe animate Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requir 0.4% —
CVE-2024-20763 MED 5.5 adobe animate Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requir 0.4% —
CVE-2023-47042 HIGH 7.8 adobe media_encoder Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0.4% —
CVE-2023-26606 HIGH 7.8 linux linux_kernel In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c. 0.4% —
CVE-2023-24910 HIGH 7.8 microsoft 365 Windows Graphics Component Elevation of Privilege Vulnerability 0.4% —
CVE-2023-23419 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.4% —
CVE-2023-23418 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.4% —
CVE-2023-23417 HIGH 7.8 microsoft windows_10_1607 Windows Partition Management Driver Elevation of Privilege Vulnerability 0.4% —
CVE-2023-21704 HIGH 7.8 microsoft sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.4% —
CVE-2023-21528 HIGH 7.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 0.4% —
CVE-2022-41291 MED 6.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. 0.4% —
CVE-2022-33646 HIGH 7.0 microsoft azure_batch Azure Batch Node Agent Elevation of Privilege Vulnerability 0.4% —
CVE-2021-46702 MED 5.5 torproject tor Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished 0.4% —
CVE-2021-4442 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li reported a syzkaller bug where the repro changes RCV SEQ _after_ restoring data in the receive queue. mprotect(0x4aa000, 12288, PROT_READ) 0.4% —
CVE-2021-4032 MED 4.4 linux linux_kernel A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU constr 0.4% —
CVE-2021-21292 MED 5.5 traccar traccar Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a 0.4% —
CVE-2020-29569 HIGH 8.8 debian debian_linux An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the f 0.4% —
CVE-2019-4101 MED 5.5 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PD_GET_DIAG_HIST and access to the diagnostic directory on the DB2 server can cause the instance to cra 0.4% —
CVE-2019-19077 MED 5.5 canonical ubuntu_linux A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14. 0.4% —
CVE-2019-18811 MED 5.5 fedoraproject fedora A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1. 0.4% —