57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-2141 | LOW 2.1 | linux linux_kernel The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill s | 0.6% | — |
| CVE-2026-48448 | HIGH 8.6 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file syst | 0.6% | — |
| CVE-2026-33858 | HIGH 8.8 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0.6% | — |
| CVE-2026-21535 | HIGH 8.2 | microsoft teams Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-21222 | MED 5.5 | microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-59240 | MED 5.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-59494 | HIGH 7.8 | microsoft azure_monitor_agent Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-47849 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation | 0.6% | — |
| CVE-2025-47713 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte | 0.6% | — |
| CVE-2023-33307 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | 0.6% | — |
| CVE-2022-35708 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0.6% | — |
| CVE-2021-32600 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information | 0.6% | — |
| CVE-2021-34760 | MED 4.8 | cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due | 0.6% | — |
| CVE-2021-1383 | MED 6.0 | cisco ios_xe Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI comma | 0.6% | — |
| CVE-2019-1857 | MED 6.1 | cisco hx220c_af_m5_firmware A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is d | 0.6% | — |
| CVE-2018-15316 | MED 5.5 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks. | 0.6% | — |
| CVE-2026-43011 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call cha | 0.6% | — |
| CVE-2025-59294 | LOW 2.1 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | 0.6% | — |
| CVE-2025-50161 | HIGH 7.3 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-46858 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== | 0.6% | — |
| CVE-2024-27066 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not ca | 0.6% | — |
| CVE-2021-46948 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handling We're starting from a TXQ label, not a TXQ type, so efx_channel_get_tx_queue() is inappropriate (and could return NULL, leading to pani | 0.6% | — |
| CVE-2023-36008 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21759 | LOW 3.3 | microsoft windows_10 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2014-0351 | MED 5.4 | fortinet fortios The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere wit | 0.6% | — |