57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-45720 | HIGH 8.2 | apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra | 0.6% | — |
| CVE-2024-33863 | CRIT 9.8 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. | 0.6% | — |
| CVE-2024-26936 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well a | 0.6% | — |
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0.6% | — |
| CVE-2021-27072 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-1846 | HIGH 7.4 | cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr | 0.6% | — |
| CVE-2019-1749 | HIGH 7.4 | cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in | 0.6% | — |
| CVE-2018-11760 | MED 5.5 | apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. | 0.6% | — |
| CVE-2024-57802 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Syzkaller reports an uninit value read from ax25cmp when sending raw message through ieee802154 implementation. ============================= | 0.6% | — |
| CVE-2024-46736 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the | 0.6% | — |
| CVE-2024-40992 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid | 0.6% | — |
| CVE-2024-38142 | HIGH 7.8 | microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-32118 | MED 6.7 | fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. | 0.6% | — |
| CVE-2023-36569 | HIGH 8.4 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-38039 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37990 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29103 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2014-4700 | MED 4.9 | citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. | 0.6% | — |
| CVE-2012-5459 | HIGH 7.9 | vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." | 0.6% | — |
| CVE-2026-80080 | HIGH 8.8 | microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-70336 | HIGH 8.8 | microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62795 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58389 | HIGH 7.5 | apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0.6% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-55968 | HIGH 7.5 | apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss | 0.6% | — |