57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-9320 | MED 5.9 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to c | 0.6% | — |
| CVE-2025-53739 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-53735 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-38248 | HIGH 7.0 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-38377 | MED 4.3 | fortinet fortianalyzer An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through | 0.6% | — |
| CVE-2022-22304 | MED 6.1 | fortinet fortiauthenticator_agent_for_microsoft_outlook_web_access An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests. | 0.6% | — |
| CVE-2021-43068 | MED 5.4 | fortinet fortiauthenticator A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. | 0.6% | — |
| CVE-2020-27170 | MED 4.7 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel | 0.6% | — |
| CVE-2014-8369 | HIGH 7.8 | debian debian_linux The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly ha | 0.6% | — |
| CVE-2013-0217 | MED 5.2 | linux linux_kernel Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions. | 0.6% | — |
| CVE-2026-65181 | HIGH 8.1 | apache impala Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | 0.6% | — |
| CVE-2026-55276 | CRIT 9.1 | apache tomcat Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, | 0.6% | — |
| CVE-2026-52998 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the devic | 0.6% | — |
| CVE-2026-8992 | HIGH 8.8 | ivanti secure_access_client An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | 0.6% | — |
| CVE-2025-53844 | HIGH 8.8 | fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. | 0.6% | — |
| CVE-2026-20835 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-20829 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-21378 | HIGH 7.8 | microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-53095 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and so | 0.6% | — |
| CVE-2024-50185 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid t | 0.6% | — |
| CVE-2024-44970 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possi | 0.6% | — |
| CVE-2023-38150 | HIGH 7.8 | microsoft windows_11_21h2 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-4147 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | 0.6% | — |
| CVE-2023-21739 | HIGH 7.0 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |