58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21596 | MED 5.3 | juniper junos A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). If an attacker sends a specific BGP UPDATE | 0.5% | — |
| CVE-2023-38175 | HIGH 7.8 | microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35364 | HIGH 8.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-28299 | MED 5.5 | microsoft visual_studio_2017 Visual Studio Spoofing Vulnerability | 0.5% | — |
| CVE-2022-42342 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations s | 0.5% | — |
| CVE-2022-1652 | HIGH 7.8 | debian debian_linux Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbit | 0.5% | — |
| CVE-2022-23276 | HIGH 7.8 | microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-40467 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36134 | HIGH 7.4 | netop vision_pro Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). | 0.5% | — |
| CVE-2019-7308 | MED 5.6 | canonical ubuntu_linux kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. | 0.5% | — |
| CVE-2015-8953 | MED 5.5 | linux linux_kernel fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer. | 0.5% | — |
| CVE-2026-75020 | HIGH 8.1 | apache apisix Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different e | 0.5% | — |
| CVE-2026-24254 | CRIT 9.8 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial | 0.5% | — |
| CVE-2026-50460 | HIGH 8.1 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-50365 | HIGH 8.0 | microsoft windows_10_1607 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.5% | — |
| CVE-2026-42900 | HIGH 8.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-31711 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: server: fix active_num_conn leak on transport allocation failure Commit 77ffbcac4e56 ("smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()") addressed the kthread_run | 0.5% | — |
| CVE-2026-32226 | MED 5.9 | microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.5% | — |
| CVE-2024-43646 | MED 6.7 | microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-43645 | MED 6.7 | microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-43631 | MED 6.7 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-0008 | MED 4.4 | paloaltonetworks pan-os A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. | 0.5% | — |
| CVE-2022-37426 | MED 4.3 | opennebula opennebula Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | 0.5% | — |
| CVE-2021-39028 | MED 5.4 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vu | 0.5% | — |
| CVE-2022-29116 | MED 4.7 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0.5% | — |