57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-29825 | MED 6.5 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2024-42004 | HIGH 7.1 | microsoft teams A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and | 0.8% | — |
| CVE-2021-1440 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of s | 0.8% | — |
| CVE-2024-20254 | CRIT 9.6 | cisco expressway Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected devic | 0.8% | — |
| CVE-2024-24860 | MED 4.6 | linux linux_kernel A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. | 0.8% | — |
| CVE-2023-35373 | MED 5.3 | microsoft mono Mono Authenticode Validation Spoofing Vulnerability | 0.8% | — |
| CVE-2022-29134 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29127 | MED 4.2 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-29123 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29122 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-26930 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22011 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28972 | MED 6.7 | fedoraproject fedora In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame | 0.8% | — |
| CVE-2020-3522 | MED 6.3 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the devic | 0.8% | — |
| CVE-2019-16010 | MED 4.8 | cisco sd-wan_firmware A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the vManage software. The vulnerability is d | 0.8% | — |
| CVE-2019-1447 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445. | 0.8% | — |
| CVE-2019-1445 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447. | 0.8% | — |
| CVE-2019-6627 | MED 5.9 | f5 ssl_orchestrator On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled. | 0.8% | — |
| CVE-2019-12881 | HIGH 7.8 | linux linux_kernel i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl ca | 0.8% | — |
| CVE-2019-7221 | HIGH 7.8 | canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. | 0.8% | — |
| CVE-2019-1594 | HIGH 7.4 | cisco nx-os A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation of Extensible Au | 0.8% | — |
| CVE-2025-47161 | HIGH 7.8 | microsoft defender_for_endpoint Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2023-39441 | MED 5.9 | apache airflow Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 | 0.8% | — |
| CVE-2021-23014 | HIGH 8.8 | f5 big-ip_advanced_web_application_firewall On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privi | 0.8% | — |
| CVE-2021-24095 | HIGH 7.0 | microsoft windows_10 DirectX Elevation of Privilege Vulnerability | 0.8% | — |