57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2006-2629 | MED 4.0 | linux linux_kernel Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes memo | 0.7% | — |
| CVE-2026-69550 | MED 6.5 | microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-65794 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-26136 | MED 6.5 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-53763 | CRIT 9.8 | microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-38163 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38616 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux | 0.7% | — |
| CVE-2023-45188 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulner | 0.7% | — |
| CVE-2020-15936 | LOW 2.6 | fortinet fortios A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets. | 0.7% | — |
| CVE-2021-40470 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40466 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40443 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-8912 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. | 0.7% | — |
| CVE-2026-26035 | CRIT 9.8 | fortinet fortiweb An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthentica | 0.7% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-24209 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |
| CVE-2025-66200 | MED 5.4 | apache http_server mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: fro | 0.7% | — |
| CVE-2025-53804 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53803 | MED 5.5 | microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-30386 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-21402 | HIGH 7.8 | microsoft office Microsoft Office OneNote Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43503 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43883 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. | 0.7% | — |
| CVE-2024-26245 | HIGH 7.8 | microsoft windows_10_1507 Windows SMB Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26755 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there are spares that can be added or removed from conf, however, if reshape is still in progres | 0.7% | — |