57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43493 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications. | 0.6% | — |
| CVE-2025-54910 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-36049 | HIGH 8.8 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. | 0.6% | — |
| CVE-2024-53176 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: During unmount, ensure all cached dir instances drop their dentry The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can race with various cached directory operations, | 0.6% | — |
| CVE-2023-25606 | MED 6.5 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated att | 0.6% | — |
| CVE-2021-24017 | MED 5.4 | fortinet fortimanager An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler. | 0.6% | — |
| CVE-2018-7268 | MED 5.5 | magnicomp sysinfo MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file p | 0.6% | — |
| CVE-2018-15326 | HIGH 7.5 | f5 big-ip_access_policy_manager In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List. | 0.6% | — |
| CVE-2026-40370 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-33118 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-59258 | MED 6.2 | microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-26639 | HIGH 7.8 | microsoft windows_10_21h2 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-21359 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-46958 | CRIT 9.1 | nextcloud desktop In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. | 0.6% | — |
| CVE-2024-21606 | HIGH 7.5 | juniper junos A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is con | 0.6% | — |
| CVE-2023-6793 | LOW 2.7 | paloaltonetworks pan-os An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage. | 0.6% | — |
| CVE-2023-28263 | MED 5.5 | microsoft visual_studio_2019 Visual Studio Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-28253 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-24945 | MED 5.5 | microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-22981 | MED 4.8 | f5 big-ip_access_policy_manager On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable | 0.6% | — |
| CVE-2020-24558 | HIGH 7.1 | trendmicro apex_one A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker mu | 0.6% | — |
| CVE-2019-5665 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does not check for hard links. This behavior may lead to code execution, denial of service or escalation of privile | 0.6% | — |
| CVE-2019-15031 | MED 4.4 | canonical ubuntu_linux In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe | 0.6% | — |
| CVE-2014-0102 | MED 5.2 | linux linux_kernel The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands. | 0.6% | — |
| CVE-2010-3865 | HIGH 7.2 | linux linux_kernel Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which tri | 0.6% | — |