58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-29207 | MED 6.5 | apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updat | 0.5% | — |
| CVE-2025-49216 | CRIT 9.8 | trendmicro trend_micro_endpoint_encryption An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | 0.5% | — |
| CVE-2024-53169 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: fix kernel crash while shutting down controller The nvme keep-alive operation, which executes at a periodic interval, could potentially sneak in while shutting down a fabric co | 0.5% | — |
| CVE-2024-49875 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: map the EBADMSG to nfserr_io to avoid warning Ext4 will throw -EBADMSG through ext4_readdir when a checksum error occurs, resulting in the following WARNING. Fix it by mapping EBADMSG | 0.5% | — |
| CVE-2024-21445 | HIGH 7.0 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-4417 | MED 6.5 | devolutions remote_desktop_manager Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with share | 0.5% | — |
| CVE-2022-20967 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnera | 0.5% | — |
| CVE-2022-30992 | MED 6.1 | acronis cyber_protect Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0.5% | — |
| CVE-2011-2183 | MED 4.0 | linux linux_kernel Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other | 0.5% | — |
| CVE-2026-78254 | HIGH 7.4 | apache ant The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker' | 0.5% | — |
| CVE-2026-69558 | HIGH 8.6 | microsoft partner_center Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-66800 | HIGH 8.6 | microsoft azure_data_factory Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-71407 | MED 5.6 | fortinet fortios A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon vi | 0.5% | — |
| CVE-2026-5272 | HIGH 8.8 | google chrome Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-20833 | MED 5.5 | microsoft windows_server_2008 Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-20825 | MED 4.4 | microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-49664 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-21271 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-56688 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport Since transport->sock has been set to NULL during reset transport, XPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the xs_ | 0.5% | — |
| CVE-2024-46855 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: fix sk refcount leaks We must put 'sk' reference before returning. | 0.5% | — |
| CVE-2024-30099 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-47136 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: zero-initialize tc skb extension on allocation Function skb_ext_add() doesn't initialize created skb extension with any value and leaves it up to the user. However, since extension of t | 0.5% | — |
| CVE-2024-21336 | LOW 2.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2023-35898 | MED 4.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. | 0.5% | — |
| CVE-2022-31676 | HIGH 7.8 | debian debian_linux VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine. | 0.5% | — |