57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0667 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0735, CVE-2020-0752. | 0.8% | — |
| CVE-2019-19057 | LOW 3.3 | broadcom brocade_fabric_operating_system_firmware Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, a | 0.8% | — |
| CVE-2018-0484 | MED 5.3 | cisco ios A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class con | 0.8% | — |
| CVE-2018-0395 | HIGH 8.8 | cisco firepower_extensible_operating_system A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The | 0.8% | — |
| CVE-2018-0257 | MED 4.3 | cisco ios_xe A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerabilit | 0.8% | — |
| CVE-2009-4131 | HIGH 7.2 | linux linux_kernel The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions. | 0.8% | — |
| CVE-2009-0054 | MED 4.3 | cisco ironport_encryption_appliance PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to cap | 0.8% | — |
| CVE-2009-0053 | MED 4.3 | cisco ironport_encryption_appliance PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obt | 0.8% | — |
| CVE-2026-71330 | HIGH 7.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-70587 | HIGH 7.5 | microsoft windows_10_1607 Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-58617 | HIGH 8.1 | microsoft 365_copilot Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-47287 | MED 6.5 | microsoft visual_studio_code Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0.8% | — |
| CVE-2025-30398 | HIGH 8.1 | microsoft nuance_powerscribe_360 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-53792 | CRIT 9.1 | microsoft azure_portal Azure Portal Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-23334 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending a request. A successful exploit of this vulnerability might lead to information disclosure. | 0.8% | — |
| CVE-2024-53948 | MED 5.3 | apache superset Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. | 0.8% | — |
| CVE-2024-44998 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() because the skb is released. | 0.8% | — |
| CVE-2024-38175 | CRIT 9.6 | microsoft azure_managed_instance_for_apache_cassandra An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-36042 | MED 6.2 | microsoft visual_studio_2019 Visual Studio Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-41105 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-41104 | MED 5.5 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-41060 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-33744 | MED 5.3 | microsoft windows_10 Windows Secure Kernel Mode Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-29964 | HIGH 7.1 | mozilla firefox A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thun | 0.8% | — |
| CVE-2021-29686 | HIGH 8.8 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015 | 0.8% | — |