57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-78989 | CRIT 9.6 | google chrome Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-63512 | MED 6.5 | microsoft sharepoint_server Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | 0.5% | — |
| CVE-2026-53434 | CRIT 9.1 | apache tomcat Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users a | 0.5% | — |
| CVE-2026-43951 | MED 6.5 | apache http_server Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. | 0.5% | — |
| CVE-2025-30383 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-30381 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-30379 | HIGH 7.8 | microsoft 365_apps Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2024-53138 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e | 0.5% | — |
| CVE-2023-20190 | MED 5.8 | cisco ios_xr A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is d | 0.5% | — |
| CVE-2022-41157 | HIGH 8.1 | webcash serp_server_2.0 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | 0.5% | — |
| CVE-2022-35749 | HIGH 7.8 | microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35746 | HIGH 7.8 | microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-29106 | HIGH 7.0 | microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-26939 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-26099 | MED 4.4 | fortinet fortimail Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphert | 0.5% | — |
| CVE-2021-24092 | HIGH 7.8 | microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2019-6699 | MED 5.4 | fortinet fortiadc An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface. | 0.5% | — |
| CVE-2019-4738 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753. | 0.5% | — |
| CVE-2019-1805 | MED 4.3 | cisco wireless_lan_controller_software A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnera | 0.5% | — |
| CVE-2017-0448 | MED 5.5 | google android An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p | 0.5% | — |
| CVE-2014-3122 | MED 4.9 | canonical ubuntu_linux The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires remo | 0.5% | — |
| CVE-2010-1966 | MED 4.6 | hp insight_control Unspecified vulnerability in HP Insight Control power management for Windows before 6.1 allows local users to read or modify data, or cause a denial of service, via unknown vectors. | 0.5% | — |
| CVE-2026-62900 | MED 5.9 | microsoft .net Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2024-43644 | HIGH 7.8 | microsoft windows_10_1507 Windows Client-Side Caching Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-20278 | MED 6.5 | cisco ios_xe A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exp | 0.5% | — |