57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-82435 | CRIT 9.8 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a singl | 0.6% | — |
| CVE-2026-80080 | HIGH 8.8 | microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-70336 | HIGH 8.8 | microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62795 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58389 | HIGH 7.5 | apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0.6% | — |
| CVE-2026-55968 | HIGH 7.5 | apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss | 0.6% | — |
| CVE-2026-43871 | HIGH 7.5 | apache thrift Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0.6% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-33414 | HIGH 7.8 | podman_project podman Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted st | 0.6% | — |
| CVE-2026-23969 | MED 6.5 | apache superset Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was | 0.6% | — |
| CVE-2025-10226 | CRIT 9.8 | axxonsoft axxon_one Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via e | 0.6% | — |
| CVE-2025-21844 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent nu | 0.6% | — |
| CVE-2024-53058 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data In case the non-paged data of a SKB carries protocol header and protocol payload to be transmitted on a certain platform | 0.6% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.6% | — |
| CVE-2022-48744 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid field-overflowing memcpy() In preparation for FORTIFY_SOURCE performing compile-time and run-time field bounds checking for memcpy(), memmove(), and memset(), avoid intentio | 0.6% | — |
| CVE-2022-20965 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control | 0.6% | — |
| CVE-2023-21531 | HIGH 7.0 | microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-34690 | HIGH 7.1 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-22215 | MED 6.5 | juniper junos A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Ser | 0.6% | — |
| CVE-2021-22033 | LOW 2.7 | vmware cloud_foundation Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. | 0.6% | — |
| CVE-2018-20976 | HIGH 7.8 | linux linux_kernel An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure. | 0.6% | — |
| CVE-2017-9489 | HIGH 8.8 | cisco dpc3939b_firmware The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF. | 0.6% | — |
| CVE-2012-1179 | MED 5.2 | linux linux_kernel The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS, related to the pmd_none_or_clear_bad function and page faults for huge pages. | 0.6% | — |
| CVE-2026-20955 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-20948 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |