IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-57802 CRIT 9.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Syzkaller reports an uninit value read from ax25cmp when sending raw message through ieee802154 implementation. ============================= 0.6%
CVE-2024-32118 MED 6.7 fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. 0.6%
CVE-2024-46736 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the 0.6%
CVE-2024-38142 HIGH 7.8 microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.6%
CVE-2024-40992 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid 0.6%
CVE-2024-35888 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: erspan: make sure erspan_base_hdr is present in skb->head syzbot reported a problem in ip6erspan_rcv() [1] Issue is that ip6erspan_rcv() (and erspan_rcv()) no longer make sure erspan_base_h 0.6%
CVE-2023-36569 HIGH 8.4 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 0.6%
CVE-2022-38039 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-37990 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2014-4700 MED 4.9 citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. 0.6%
CVE-2012-5459 HIGH 7.9 vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." 0.6%
CVE-2026-40361 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-21281 HIGH 7.8 microsoft windows_10_1507 Microsoft COM for Windows Elevation of Privilege Vulnerability 0.6%
CVE-2024-33863 CRIT 9.8 linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. 0.6%
CVE-2024-26936 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well a 0.6%
CVE-2023-23395 LOW 3.1 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 0.6%
CVE-2021-27072 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2019-1846 HIGH 7.4 cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr 0.6%
CVE-2019-1749 HIGH 7.4 cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in 0.6%
CVE-2018-11760 MED 5.5 apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. 0.6%
CVE-2026-78519 HIGH 8.8 microsoft 365_apps Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-69297 MED 6.5 microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-68823 CRIT 9.1 microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 0.6%
CVE-2026-50525 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2025-36049 HIGH 8.8 ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. 0.6%