IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-43493 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications. 0.6%
CVE-2025-54910 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-36049 HIGH 8.8 ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. 0.6%
CVE-2024-53176 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: During unmount, ensure all cached dir instances drop their dentry The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can race with various cached directory operations, 0.6%
CVE-2023-25606 MED 6.5 fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated att 0.6%
CVE-2021-24017 MED 5.4 fortinet fortimanager An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler. 0.6%
CVE-2018-7268 MED 5.5 magnicomp sysinfo MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file p 0.6%
CVE-2018-15326 HIGH 7.5 f5 big-ip_access_policy_manager In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List. 0.6%
CVE-2026-40370 HIGH 8.8 microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. 0.6%
CVE-2026-33118 MED 4.3 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2025-59258 MED 6.2 microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-26639 HIGH 7.8 microsoft windows_10_21h2 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-21359 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability 0.6%
CVE-2024-46958 CRIT 9.1 nextcloud desktop In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. 0.6%
CVE-2024-21606 HIGH 7.5 juniper junos A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is con 0.6%
CVE-2023-6793 LOW 2.7 paloaltonetworks pan-os An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage. 0.6%
CVE-2023-28263 MED 5.5 microsoft visual_studio_2019 Visual Studio Information Disclosure Vulnerability 0.6%
CVE-2023-28253 MED 5.5 microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability 0.6%
CVE-2023-24945 MED 5.5 microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability 0.6%
CVE-2021-22981 MED 4.8 f5 big-ip_access_policy_manager On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable 0.6%
CVE-2020-24558 HIGH 7.1 trendmicro apex_one A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker mu 0.6%
CVE-2019-5665 HIGH 7.8 nvidia gpu_driver NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does not check for hard links. This behavior may lead to code execution, denial of service or escalation of privile 0.6%
CVE-2019-15031 MED 4.4 canonical ubuntu_linux In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe 0.6%
CVE-2014-0102 MED 5.2 linux linux_kernel The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands. 0.6%
CVE-2010-3865 HIGH 7.2 linux linux_kernel Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which tri 0.6%