57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-50171 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - don't sleep when in softirq When kunpeng920 encryption driver is used to deencrypt and decrypt packets during the softirq, it is not allowed to use mutex lock. The ke | 0.3% | — |
| CVE-2022-49471 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rtw89: cfo: check mac_id to avoid out-of-bounds Somehow, hardware reports incorrect mac_id and pollute memory. Check index before we access the array. UBSAN: array-index-out-of-bounds in | 0.3% | — |
| CVE-2022-39190 | MED 5.5 | debian debian_linux An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain. | 0.3% | — |
| CVE-2022-36879 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | 0.3% | — |
| CVE-2022-26115 | MED 5.9 | fortinet fortisandbox A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords. | 0.3% | — |
| CVE-2021-38166 | HIGH 7.8 | debian debian_linux In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability. | 0.3% | — |
| CVE-2020-1624 | MED 5.5 | juniper junos_os_evolved A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | 0.3% | — |
| CVE-2020-1623 | MED 5.5 | juniper junos_os_evolved A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1. | 0.3% | — |
| CVE-2020-1622 | MED 5.5 | juniper junos_os_evolved A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | 0.3% | — |
| CVE-2020-1621 | MED 5.5 | juniper junos_os_evolved A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | 0.3% | — |
| CVE-2020-1620 | MED 5.5 | juniper junos_os_evolved A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | 0.3% | — |
| CVE-2017-18249 | HIGH 7.0 | debian debian_linux The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads. | 0.3% | — |
| CVE-2016-2069 | HIGH 7.4 | canonical ubuntu_linux Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU. | 0.3% | — |
| CVE-2013-5556 | MED 6.8 | cisco nexus_1000v The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows loca | 0.3% | — |
| CVE-2011-0699 | HIGH 7.0 | linux linux_kernel Integer signedness error in the btrfs_ioctl_space_info function in the Linux kernel 2.6.37 allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted slot value. | 0.3% | — |
| CVE-2010-5163 | MED 6.2 | kaspersky kaspersky_internet_security_2010 Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via | 0.3% | — |
| CVE-2010-5162 | MED 6.2 | gdata totalcare_2010 Race condition in G DATA TotalCare 2010 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space m | 0.3% | — |
| CVE-2026-70330 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70304 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-64445 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() is called w | 0.3% | — |
| CVE-2026-62708 | MED 6.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0.3% | — |
| CVE-2026-61398 | CRIT 9.1 | apache cloudstack Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended | 0.3% | — |
| CVE-2026-47894 | MED 4.9 | vmware spring_cloud_config Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config | 0.3% | — |
| CVE-2026-33115 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-33114 | HIGH 8.4 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |