57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20934 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20848 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-24039 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38119 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38057 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38034 | HIGH 7.8 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-24749 | HIGH 7.5 | geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi | 0.8% | — |
| CVE-2023-33162 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-34395 | HIGH 7.8 | apache apache-airflow-providers-odbc Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver pa | 0.8% | — |
| CVE-2022-31772 | MED 5.3 | ibm mq IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335. | 0.8% | — |
| CVE-2022-2778 | CRIT 9.8 | octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 0.8% | — |
| CVE-2022-25990 | MED 5.3 | f5 f5os-a On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.8% | — |
| CVE-2021-1727 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0868 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0867. | 0.8% | — |
| CVE-2020-0867 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0868. | 0.8% | — |
| CVE-2020-0857 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0844 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0808 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0631 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |
| CVE-2019-15220 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver. | 0.8% | — |
| CVE-2019-15211 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory. | 0.8% | — |
| CVE-2015-5258 | HIGH 8.8 | fedoraproject fedora Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3. | 0.8% | — |
| CVE-2010-4250 | MED 4.9 | linux linux_kernel Memory leak in the inotify_init1 function in fs/notify/inotify/inotify_user.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory consumption) via vectors involving failed attempts to create files. | 0.8% | — |
| CVE-2005-4868 | HIGH 7.1 | ibm db2_universal_database Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service. | 0.8% | — |
| CVE-2025-21363 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |