IT
57.298 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-42286 HIGH 7.8 microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability 0.5%
CVE-2021-42283 HIGH 8.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41377 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-41370 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41367 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41366 HIGH 7.8 microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability 0.5%
CVE-2021-36957 HIGH 7.8 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0.5%
CVE-2021-3564 MED 5.5 debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi 0.5%
CVE-2020-5869 CRIT 9.1 f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. 0.5%
CVE-2015-8569 LOW 2.3 linux linux_kernel The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism 0.5%
CVE-2011-1182 LOW 3.6 linux linux_kernel kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. 0.5%
CVE-2011-1023 MED 4.9 linux linux_kernel The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) tra 0.5%
CVE-2009-1630 MED 4.4 canonical ubuntu_linux The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions 0.5%
CVE-2026-53180 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle_remote_up() tmigr_handle_remote_cpu() skips timer_expire_remote() when cpu == smp_processor_id(), assuming the local softirq path already handl 0.5%
CVE-2026-48317 CRIT 9.6 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker coul 0.5%
CVE-2026-31909 HIGH 7.5 apache ofbiz Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.5%
CVE-2025-66170 MED 6.5 apache cloudstack The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backup 0.5%
CVE-2025-29839 MED 4.0 microsoft windows_10_1507 Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2024-55913 MED 5.3 ibm concert IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. 0.5%
CVE-2024-20322 MED 5.8 cisco ios_xr A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignme 0.5%
CVE-2023-28963 MED 5.3 juniper junos An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Netwo 0.5%
CVE-2023-20242 MED 4.8 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) c 0.5%
CVE-2022-38016 HIGH 8.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5%
CVE-2022-37984 HIGH 7.8 microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability 0.5%
CVE-2022-37983 HIGH 7.8 microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5%