IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-45720 HIGH 8.2 apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra 0.6%
CVE-2024-33863 CRIT 9.8 linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. 0.6%
CVE-2024-26936 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well a 0.6%
CVE-2023-23395 LOW 3.1 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 0.6%
CVE-2021-27072 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2019-1846 HIGH 7.4 cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr 0.6%
CVE-2019-1749 HIGH 7.4 cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in 0.6%
CVE-2018-11760 MED 5.5 apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. 0.6%
CVE-2024-57802 CRIT 9.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Syzkaller reports an uninit value read from ax25cmp when sending raw message through ieee802154 implementation. ============================= 0.6%
CVE-2024-46736 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the 0.6%
CVE-2024-40992 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid 0.6%
CVE-2024-38142 HIGH 7.8 microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.6%
CVE-2024-32118 MED 6.7 fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. 0.6%
CVE-2023-36569 HIGH 8.4 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 0.6%
CVE-2022-38039 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-37990 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-29103 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2014-4700 MED 4.9 citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. 0.6%
CVE-2012-5459 HIGH 7.9 vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." 0.6%
CVE-2026-80080 HIGH 8.8 microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-70336 HIGH 8.8 microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62795 HIGH 8.8 microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-58389 HIGH 7.5 apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.6%
CVE-2026-56188 CRIT 9.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-55968 HIGH 7.5 apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss 0.6%