57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30064 | HIGH 8.8 | microsoft windows_server_2022 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-35309 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-33154 | HIGH 7.8 | microsoft windows_10_1507 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-27725 | MED 4.3 | f5 big-ip_domain_name_system In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those | 0.8% | — |
| CVE-2016-5202 | CRIT 9.1 | google chrome browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data t | 0.8% | — |
| CVE-2016-2084 | HIGH 7.4 | f5 big-ip_access_policy_manager F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4. | 0.8% | — |
| CVE-2026-66303 | MED 6.5 | microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-67633 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. | 0.8% | — |
| CVE-2025-4615 | HIGH 7.2 | paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu | 0.8% | — |
| CVE-2024-38198 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38056 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-38055 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-41064 | MED 5.8 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-23263 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-26442 | HIGH 7.0 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-3045 | MED 4.9 | paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 | 0.8% | — |
| CVE-2021-26890 | HIGH 7.8 | microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-1660 | HIGH 8.3 | juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt | 0.8% | — |
| CVE-2020-3384 | HIGH 8.2 | cisco data_center_network_manager A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerabilit | 0.8% | — |
| CVE-2018-0208 | MED 5.4 | cisco email_encryption A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of th | 0.8% | — |
| CVE-2026-43499 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when | 0.8% | — |
| CVE-2026-40415 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-4598 | MED 4.7 | debian debian_linux A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/ | 0.8% | — |
| CVE-2024-49996 | CRIT 9.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's s | 0.8% | — |
| CVE-2022-45412 | HIGH 8.8 | mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems | 0.8% | — |