57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-39016 | MED 4.3 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed for t | 0.6% | — |
| CVE-2022-20765 | MED 4.8 | cisco ucs_director A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vuln | 0.6% | — |
| CVE-2021-34460 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34511 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34488 | HIGH 7.8 | microsoft windows_10 Windows Console Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34477 | HIGH 7.8 | microsoft .net_education_bundle_sdk_install_tool Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2020-5025 | HIGH 7.8 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root | 0.6% | — |
| CVE-2021-1218 | MED 5.4 | cisco smart_software_manager_on-prem A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in | 0.6% | — |
| CVE-2020-3314 | MED 6.1 | cisco advanced_malware_protection_for_endpoints A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP | 0.6% | — |
| CVE-2018-19824 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c. | 0.6% | — |
| CVE-2018-0306 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker coul | 0.6% | — |
| CVE-2005-0124 | LOW 2.1 | linux linux_kernel The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a | 0.6% | — |
| CVE-2002-1233 | LOW 2.6 | apache http_server A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on tempora | 0.6% | — |
| CVE-2026-69416 | MED 5.7 | microsoft windows_10_1607 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69405 | MED 5.7 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-76986 | MED 6.1 | apache wicket Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — | 0.6% | — |
| CVE-2026-50481 | CRIT 9.9 | microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50528 | HIGH 8.2 | microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2026-54475 | HIGH 7.5 | apache activemq Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only ch | 0.6% | — |
| CVE-2026-43037 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as str | 0.6% | — |
| CVE-2026-26149 | CRIT 9.0 | microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-59234 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-47181 | HIGH 8.8 | microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2023-36888 | MED 6.3 | microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Tampering Vulnerability | 0.6% | — |