57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-26156 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-23657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-22720 | HIGH 8.0 | vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, | 0.4% | — |
| CVE-2026-10928 | HIGH 8.8 | google chrome Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-10904 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-60718 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-38057 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb. | 0.4% | — |
| CVE-2025-36048 | HIGH 7.2 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | 0.4% | — |
| CVE-2025-22891 | HIGH 7.5 | f5 big-ip_policy_enforcement_manager When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versio | 0.4% | — |
| CVE-2025-21673 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realiz | 0.4% | — |
| CVE-2024-35834 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue. | 0.4% | — |
| CVE-2023-41836 | LOW 3.5 | fortinet fortisandbox An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.4, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, | 0.4% | — |
| CVE-2023-41749 | HIGH 7.5 | acronis agent Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) before build 32047, Acronis Cyber Protect 15 (Windows) before build 35979. | 0.4% | — |
| CVE-2023-39189 | MED 5.1 | fedoraproject fedora A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the user mode controlled opt_num field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading | 0.4% | — |
| CVE-2023-35299 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-31132 | HIGH 7.8 | cacti cacti Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files | 0.4% | — |
| CVE-2022-29113 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-28877 | MED 4.3 | f-secure elements_endpoint_protection This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can be abused for local privilege escalation on affected F-Secure & WithSecure windows endpoint products. An attacker must have code execution r | 0.4% | — |
| CVE-2021-34778 | MED 4.3 | cisco business_220-16p-2g_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to | 0.4% | — |
| CVE-2021-34777 | MED 4.3 | cisco business_220-16p-2g_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to | 0.4% | — |
| CVE-2021-34776 | MED 4.3 | cisco business_220-16p-2g_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to | 0.4% | — |
| CVE-2021-34775 | MED 4.3 | cisco business_220-16p-2g_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to | 0.4% | — |
| CVE-2021-33599 | MED 4.6 | f-secure atlant A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will | 0.4% | — |
| CVE-2021-22932 | HIGH 7.5 | citrix sharefile_storagezones_controller An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if the | 0.4% | — |
| CVE-2019-1883 | HIGH 7.8 | cisco integrated_management_controller_supervisor A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerabilit | 0.4% | — |