57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-35795 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30132 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-19965 | MED 4.7 | canonical ubuntu_linux In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5. | 0.7% | — |
| CVE-2019-5538 | MED 5.9 | vmware vcenter_server Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter | 0.7% | — |
| CVE-2019-5537 | MED 5.9 | vmware vcenter_server Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter | 0.7% | — |
| CVE-2018-7191 | MED 5.5 | linux linux_kernel In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containi | 0.7% | — |
| CVE-2013-2929 | LOW 3.3 | linux linux_kernel The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c an | 0.7% | — |
| CVE-2026-42782 | HIGH 7.2 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class sta | 0.7% | — |
| CVE-2026-20828 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | 0.7% | — |
| CVE-2025-47169 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-56736 | MED 6.5 | apache hertzbeat Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue. | 0.7% | — |
| CVE-2025-26865 | LOW 3.5 | apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which | 0.7% | — |
| CVE-2024-57973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof | 0.7% | — |
| CVE-2024-38210 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38209 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-48829 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger t | 0.7% | — |
| CVE-2024-27254 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813. | 0.7% | — |
| CVE-2023-36860 | HIGH 7.1 | intel unison_software Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0.7% | — |
| CVE-2023-20227 | HIGH 8.6 | cisco ios_xe A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of c | 0.7% | — |
| CVE-2023-20176 | MED 5.8 | cisco catalyst_9124_firmware A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this | 0.7% | — |
| CVE-2023-20033 | HIGH 8.6 | cisco ios_xe A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vul | 0.7% | — |
| CVE-2023-4273 | MED 6.0 | debian debian_linux A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging t | 0.7% | — |
| CVE-2022-35842 | LOW 3.7 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP an | 0.7% | — |
| CVE-2022-24484 | MED 5.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-23268 | MED 6.5 | microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |