57.298 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42286 | HIGH 7.8 | microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42283 | HIGH 8.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41377 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41370 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41367 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41366 | HIGH 7.8 | microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36957 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-3564 | MED 5.5 | debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi | 0.5% | — |
| CVE-2020-5869 | CRIT 9.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. | 0.5% | — |
| CVE-2015-8569 | LOW 2.3 | linux linux_kernel The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism | 0.5% | — |
| CVE-2011-1182 | LOW 3.6 | linux linux_kernel kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. | 0.5% | — |
| CVE-2011-1023 | MED 4.9 | linux linux_kernel The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) tra | 0.5% | — |
| CVE-2009-1630 | MED 4.4 | canonical ubuntu_linux The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions | 0.5% | — |
| CVE-2026-53180 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle_remote_up() tmigr_handle_remote_cpu() skips timer_expire_remote() when cpu == smp_processor_id(), assuming the local softirq path already handl | 0.5% | — |
| CVE-2026-48317 | CRIT 9.6 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker coul | 0.5% | — |
| CVE-2026-31909 | HIGH 7.5 | apache ofbiz Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2025-66170 | MED 6.5 | apache cloudstack The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backup | 0.5% | — |
| CVE-2025-29839 | MED 4.0 | microsoft windows_10_1507 Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2024-55913 | MED 5.3 | ibm concert IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | 0.5% | — |
| CVE-2024-20322 | MED 5.8 | cisco ios_xr A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignme | 0.5% | — |
| CVE-2023-28963 | MED 5.3 | juniper junos An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Netwo | 0.5% | — |
| CVE-2023-20242 | MED 4.8 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) c | 0.5% | — |
| CVE-2022-38016 | HIGH 8.8 | microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-37984 | HIGH 7.8 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-37983 | HIGH 7.8 | microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.5% | — |