56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.966 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-0387 | HIGH 8.0 | cisco telepresence_multipoint_switch The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to | 2.0% | — |
| CVE-2026-48578 | HIGH 7.9 | microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48576 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2026-48575 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-48573 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2026-48570 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-48568 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-48346 | HIGH 7.9 | adobe animate Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | 0.3% | — |
| CVE-2026-47656 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-46076 | HIGH 7.9 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enab | 0.1% | — |
| CVE-2026-45654 | HIGH 7.9 | microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-45588 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-44629 | HIGH 7.9 | Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers. | 0.1% | — |
| CVE-2026-43133 | HIGH 7.9 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields con | 0.1% | — |
| CVE-2026-41217 | HIGH 7.9 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a s | 0.1% | — |
| CVE-2025-49707 | HIGH 7.9 | microsoft dcadsv5-series_azure_vm_firmware Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | 0.4% | — |
| CVE-2024-50139 | HIGH 7.9 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix shift-out-of-bounds bug Fix a shift-out-of-bounds bug reported by UBSAN when running VM with MTE enabled host kernel. UBSAN: shift-out-of-bounds in arch/arm64/kvm/sys_regs.c | 0.2% | — |
| CVE-2024-40953 | HIGH 7.9 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin() Use {READ,WRITE}_ONCE() to access kvm->last_boosted_vcpu to ensure the loads and stores are atomic. In the extremely unlikely | 0.2% | — |
| CVE-2024-22254 | HIGH 7.9 | vmware cloud_foundation VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. | 0.5% | — |
| CVE-2023-49145 | HIGH 7.9 | apache nifi Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON | 1.2% | — |
| CVE-2023-46691 | HIGH 7.9 | intel power_gadget Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28741 | HIGH 7.9 | intel quickassist_technology Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-0266 | HIGH 7.9 | debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W | 3.7% | |
| CVE-2022-21995 | HIGH 7.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-20855 | HIGH 7.9 | cisco ios_xe A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an authenticated, local attacker to escape the restricted controller shell and execute arbitrary commands on the | 0.4% | — |