57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-47140 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Clear DMA ops when switching domain Since commit 08a27c1c3ecf ("iommu: Add support to change default domain of an iommu group") a user can switch a device between IOMMU and direct | 0.6% | — |
| CVE-2021-31382 | MED 6.5 | juniper junos On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the device's interfaces with incorrect fir | 0.6% | — |
| CVE-2020-1152 | MED 5.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerability, an attacke | 0.6% | — |
| CVE-2019-15222 | MED 4.6 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/helper.c (motu_microbookii) driver. | 0.6% | — |
| CVE-2018-0249 | MED 4.3 | cisco aironet_access_point_software A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio | 0.6% | — |
| CVE-2018-0014 | MED 4.3 | juniper screenos Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Netwo | 0.6% | — |
| CVE-2017-12334 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie | 0.6% | — |
| CVE-2026-68823 | CRIT 9.1 | microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-50525 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2025-32721 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-23250 | HIGH 7.6 | nvidia nemo NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0.6% | — |
| CVE-2025-21403 | MED 6.4 | microsoft on-prem_data_gateway On-Premises Data Gateway Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-21304 | HIGH 7.8 | microsoft windows_10_1607 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43527 | HIGH 7.8 | microsoft windows_11_24h2 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43514 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38253 | HIGH 7.8 | microsoft windows_11_21h2 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38252 | HIGH 7.8 | microsoft windows_10_1607 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-20116 | MED 6.8 | cisco unified_communications_manager A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a d | 0.6% | — |
| CVE-2022-26921 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-22979 | MED 6.1 | f5 big-ip_access_policy_manager On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when F | 0.6% | — |
| CVE-2020-9290 | HIGH 7.8 | fortinet forticlient An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrar | 0.6% | — |
| CVE-2014-6385 | MED 6.1 | juniper junos Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.3R8, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1 | 0.6% | — |
| CVE-2004-2343 | HIGH 7.2 | apache http_server Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess | 0.6% | — |
| CVE-2026-40361 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21281 | HIGH 7.8 | microsoft windows_10_1507 Microsoft COM for Windows Elevation of Privilege Vulnerability | 0.6% | — |