57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-3145 | MED 4.9 | canonical ubuntu_linux The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and syste | 0.6% | — |
| CVE-2014-2115 | MED 6.8 | cisco emergency_responder Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250. | 0.6% | — |
| CVE-2014-1446 | LOW 1.9 | linux linux_kernel The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an | 0.6% | — |
| CVE-2026-72987 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-57983 | HIGH 8.7 | microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2025-53378 | HIGH 7.6 | trendmicro worry-free_business_security_services A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affe | 0.6% | — |
| CVE-2025-26521 | HIGH 8.1 | apache cloudstack When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the p | 0.6% | — |
| CVE-2025-32720 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-21375 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21367 | HIGH 7.8 | microsoft windows_10_1809 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-48743 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix | 0.6% | — |
| CVE-2024-38618 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for | 0.6% | — |
| CVE-2024-20405 | MED 4.8 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied | 0.6% | — |
| CVE-2023-20862 | MED 6.3 | netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa | 0.6% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0.6% | — |
| CVE-2022-37971 | HIGH 7.1 | microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-31185 | MED 5.5 | microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability | 0.6% | — |
| CVE-2021-28443 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0.6% | — |
| CVE-2026-55799 | CRIT 9.8 | apache ranger Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.6% | — |
| CVE-2026-24299 | MED 5.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-20862 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-38201 | HIGH 7.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-35869 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all child | 0.6% | — |
| CVE-2023-34460 | MED 4.8 | tauri tauri Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), | 0.6% | — |
| CVE-2022-43927 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671. | 0.6% | — |