57.954 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.954 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0806 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0772. | 0.8% | — |
| CVE-2013-5527 | MED 5.7 | cisco ios The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030. | 0.8% | — |
| CVE-2011-1082 | MED 4.9 | linux linux_kernel fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory | 0.8% | — |
| CVE-2026-64609 | CRIT 9.1 | apache fory Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that d | 0.8% | — |
| CVE-2024-30102 | HIGH 7.3 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-47245 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut | 0.8% | — |
| CVE-2022-48666 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still avai | 0.8% | — |
| CVE-2022-30135 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-38662 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-1146 | MED 6.6 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially craf | 0.8% | — |
| CVE-2020-1130 | MED 6.6 | microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp | 0.8% | — |
| CVE-2019-7960 | HIGH 7.8 | adobe animate_cc Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. | 0.8% | — |
| CVE-2017-4926 | MED 5.4 | vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page. | 0.8% | — |
| CVE-2025-59200 | HIGH 7.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. | 0.8% | — |
| CVE-2024-49766 | MED 5.3 | palletsprojects werkzeug Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially | 0.8% | — |
| CVE-2022-35757 | HIGH 7.3 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-0575 | HIGH 7.2 | yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula | 0.8% | — |
| CVE-2022-43285 | HIGH 7.5 | f5 njs Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. | 0.8% | — |
| CVE-2022-30226 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-22022 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1702 | HIGH 7.8 | microsoft windows_10 Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1693 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1655 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1654 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1653 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0.8% | — |