57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58718 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-10200 | HIGH 8.8 | google chrome Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.6% | — |
| CVE-2025-55673 | MED 4.3 | apache superset When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, | 0.6% | — |
| CVE-2025-26679 | HIGH 7.8 | microsoft windows_10_1507 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-35854 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The mig | 0.6% | — |
| CVE-2023-44152 | CRIT 9.1 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | 0.6% | — |
| CVE-2023-28249 | MED 6.2 | microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-3619 | LOW 3.5 | linux linux_kernel A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended | 0.6% | — |
| CVE-2021-22041 | MED 6.7 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runnin | 0.6% | — |
| CVE-2020-13884 | HIGH 7.8 | citrix workspace_app Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application. | 0.6% | — |
| CVE-2019-6692 | HIGH 7.8 | fortinet forticlient A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL. | 0.6% | — |
| CVE-2017-0451 | MED 4.7 | google android An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc | 0.6% | — |
| CVE-2016-1424 | MED 6.5 | cisco ios Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132. | 0.6% | — |
| CVE-2026-59762 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. T | 0.6% | — |
| CVE-2026-20244 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20243 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20217 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imp | 0.6% | — |
| CVE-2026-20216 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An | 0.6% | — |
| CVE-2026-20215 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imprope | 0.6% | — |
| CVE-2026-20214 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20213 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imprope | 0.6% | — |
| CVE-2026-24178 | CRIT 9.8 | nvidia nvflare NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege es | 0.6% | — |
| CVE-2025-23303 | HIGH 7.8 | nvidia nemo NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0.6% | — |
| CVE-2025-47980 | MED 6.2 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-26681 | MED 6.7 | microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |