57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-8480 | MED 4.9 | linux linux_kernel The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer derefere | 0.6% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-43501 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, | 0.6% | — |
| CVE-2026-34615 | CRIT 9.3 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject maliciou | 0.6% | — |
| CVE-2025-27739 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27731 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27730 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27476 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27467 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-26674 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-26666 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-27427 | MED 4.3 | apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo | 0.6% | — |
| CVE-2021-32584 | MED 5.3 | fortinet fortiwlc An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain ar | 0.6% | — |
| CVE-2024-40587 | MED 6.7 | fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or | 0.6% | — |
| CVE-2024-50215 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after | 0.6% | — |
| CVE-2024-38122 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38118 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-23015 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processin | 0.6% | — |
| CVE-2021-31354 | HIGH 7.1 | juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause | 0.6% | — |
| CVE-2016-6427 | HIGH 8.8 | cisco unified_contact_center_express Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bu | 0.6% | — |
| CVE-2016-6417 | HIGH 8.8 | cisco firesight_system_software Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. | 0.6% | — |
| CVE-2026-67631 | CRIT 9.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-29168 | HIGH 7.3 | apache http_server Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the | 0.6% | — |
| CVE-2024-41743 | HIGH 7.5 | ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources. | 0.6% | — |
| CVE-2024-39792 | HIGH 7.5 | f5 nginx_plus When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.6% | — |