57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-33065 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33063 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33061 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33060 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33059 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33058 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-33052 | MED 5.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-24069 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-21278 | MED 6.2 | microsoft windows_10_1507 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 0.6% | — |
| CVE-2024-28907 | HIGH 7.8 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-20195 | MED 4.7 | cisco identity_services_engine Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilitie | 0.6% | — |
| CVE-2021-39076 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585. | 0.6% | — |
| CVE-2020-3968 | HIGH 8.2 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xH | 0.6% | — |
| CVE-2020-13974 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to | 0.6% | — |
| CVE-2019-17388 | HIGH 7.8 | aviatrix vpn_client Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. | 0.6% | — |
| CVE-2018-3989 | MED 4.3 | wibu wibukey An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in k | 0.6% | — |
| CVE-2018-18021 | HIGH 7.1 | canonical ubuntu_linux arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (w | 0.6% | — |
| CVE-2014-2186 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj81777. | 0.6% | — |
| CVE-2013-1109 | MED 6.8 | cisco webex_training_center Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID | 0.6% | — |
| CVE-2008-2729 | MED 4.9 | linux linux_kernel arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information. | 0.6% | — |
| CVE-2005-3359 | MED 4.9 | linux linux_kernel The atm module in Linux kernel 2.6 before 2.6.14 allows local users to cause a denial of service (panic) via certain socket calls that produce inconsistent reference counts for loadable protocol modules. | 0.6% | — |
| CVE-2026-50414 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50398 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-58608 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-21247 | HIGH 7.3 | microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.6% | — |