57.435 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.435 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43230 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/rds: Clear reconnect pending bit When canceling the reconnect worker, care must be taken to reset the reconnect-pending bit. If the reconnect worker has not yet been scheduled before it | 0.5% | — |
| CVE-2026-43226 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_ | 0.5% | — |
| CVE-2026-32208 | HIGH 8.8 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-29170 | MED 6.1 | apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v | 0.5% | — |
| CVE-2026-23456 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checkin | 0.5% | — |
| CVE-2026-21524 | HIGH 7.4 | microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-21521 | HIGH 7.4 | microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-21405 | HIGH 7.3 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21183 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21182 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-45009 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == 0) ... before decrementing the add_addr_accepted counte | 0.5% | — |
| CVE-2023-21815 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2022-22244 | MED 5.3 | juniper junos An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss | 0.5% | — |
| CVE-2022-20684 | HIGH 7.4 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpec | 0.5% | — |
| CVE-2021-38638 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38630 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38628 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38626 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38625 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36954 | HIGH 8.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2020-5917 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure. | 0.5% | — |