57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-42342 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations s | 0.5% | — |
| CVE-2022-23276 | HIGH 7.8 | microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-1652 | HIGH 7.8 | debian debian_linux Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbit | 0.5% | — |
| CVE-2021-40467 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36134 | HIGH 7.4 | netop vision_pro Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). | 0.5% | — |
| CVE-2019-7308 | MED 5.6 | canonical ubuntu_linux kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. | 0.5% | — |
| CVE-2015-8953 | MED 5.5 | linux linux_kernel fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer. | 0.5% | — |
| CVE-2026-65789 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-45171 | HIGH 8.8 | paloaltonetworks idira_privileged_session_manager Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberAr | 0.5% | — |
| CVE-2026-30778 | HIGH 7.5 | apache skywalking The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue. | 0.5% | — |
| CVE-2026-20819 | MED 5.5 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2024-53146 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into s | 0.5% | — |
| CVE-2023-5808 | HIGH 7.6 | hitachi vantara_hitachi_network_attached_storage SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be bar | 0.5% | — |
| CVE-2023-45871 | HIGH 7.5 | debian debian_linux An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU. | 0.5% | — |
| CVE-2023-28235 | MED 6.8 | microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2021-43239 | HIGH 7.1 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42312 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36968 | HIGH 7.8 | microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-26931 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (suc | 0.5% | — |
| CVE-2021-23018 | HIGH 7.4 | f5 nginx_controller Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster. | 0.5% | — |
| CVE-2020-15935 | MED 4.3 | fortinet fortiadc A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating th | 0.5% | — |
| CVE-2017-7218 | HIGH 7.8 | paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters. | 0.5% | — |
| CVE-2016-9221 | MED 4.3 | cisco aironet_access_point_software A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This v | 0.5% | — |
| CVE-2015-8816 | MED 6.8 | linux linux_kernel The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or | 0.5% | — |
| CVE-2026-79048 | HIGH 8.8 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |