57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-54026 | MED 4.3 | fortinet fortisandbox An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, Fo | 0.4% | — |
| CVE-2024-49535 | MED 6.3 | adobe acrobat Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input conta | 0.4% | — |
| CVE-2024-48892 | MED 6.8 | fortinet fortisoar A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. | 0.4% | — |
| CVE-2024-26228 | HIGH 7.8 | microsoft windows_10_1507 Windows Cryptographic Services Security Feature Bypass Vulnerability | 0.4% | — |
| CVE-2023-44328 | MED 5.5 | adobe bridge Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation | 0.4% | — |
| CVE-2023-42755 | MED 6.5 | debian debian_linux A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to | 0.4% | — |
| CVE-2022-25946 | HIGH 8.7 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role | 0.4% | — |
| CVE-2020-8601 | HIGH 7.8 | trendmicro vulnerability_protection Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory. | 0.4% | — |
| CVE-2020-4170 | MED 4.3 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406. | 0.4% | — |
| CVE-2018-1091 | MED 5.5 | linux linux_kernel In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be triggered from unprivileged userspace during a core dump on a POWER host due to a missing processor feature check and an erron | 0.4% | — |
| CVE-2017-10741 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121." | 0.4% | — |
| CVE-2014-2678 | MED 4.7 | fedoraproject fedora The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a | 0.4% | — |
| CVE-2011-2518 | MED 4.9 | linux linux_kernel The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unsp | 0.4% | — |
| CVE-2011-2182 | HIGH 7.2 | linux linux_kernel The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive | 0.4% | — |
| CVE-2010-0007 | LOW 2.1 | linux linux_kernel net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restriction | 0.4% | — |
| CVE-2026-68817 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-68814 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-68812 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-64914 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-62886 | HIGH 7.8 | microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-58651 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-58641 | HIGH 7.8 | microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-58614 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-58155 | CRIT 9.3 | apache traffic_server Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recom | 0.4% | — |
| CVE-2026-54997 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | 0.4% | — |