58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30991 | MED 6.1 | acronis cyber_protect HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0.5% | — |
| CVE-2019-1605 | HIGH 7.8 | cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to incorrect input validation in the NX-API feature. An attacker could exploit this vulnerabi | 0.5% | — |
| CVE-2018-10940 | MED 5.5 | debian debian_linux The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory. | 0.5% | — |
| CVE-2015-4330 | MED 6.9 | cisco telepresence_video_communication_server_software A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556. | 0.5% | — |
| CVE-2010-4157 | MED 6.2 | fedoraproject fedora Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an | 0.5% | — |
| CVE-2026-26137 | CRIT 9.9 | microsoft 365_copilot_chat Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2023-53338 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: lwt: Fix return values of BPF xmit ops BPF encap ops can return different types of positive values, such like NET_RX_DROP, NET_XMIT_CN, NETDEV_TX_BUSY, and so on, from function skb_do_redire | 0.5% | — |
| CVE-2024-53178 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: Don't leak cfid when reconnect races with open_cached_dir open_cached_dir() may either race with the tcon reconnection even before compound_send_recv() or directly trigger a reconnectio | 0.5% | — |
| CVE-2024-50284 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix the missing xa_store error check xa_store() can fail, it return xa_err(-EINVAL) if the entry cannot be stored in an XArray, or xa_err(-ENOMEM) if memory allocation failed, so chec | 0.5% | — |
| CVE-2024-30395 | HIGH 7.5 | juniper junos An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is received over an establish | 0.5% | — |
| CVE-2022-0027 | MED 4.3 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including inc | 0.5% | — |
| CVE-2018-1922 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858. | 0.5% | — |
| CVE-2006-6056 | MED 4.9 | linux linux_kernel Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demo | 0.5% | — |
| CVE-2026-77487 | HIGH 8.8 | microsoft sql_server_2017 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-77483 | HIGH 8.8 | microsoft sql_server_2017 Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-77480 | HIGH 8.8 | microsoft sql_server_2017 Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-73028 | HIGH 8.8 | microsoft sql_server_2017 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-62872 | HIGH 8.8 | microsoft .net_framework Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-42535 | CRIT 9.1 | apache http_server A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes t | 0.5% | — |
| CVE-2026-9119 | HIGH 8.8 | google chrome Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2025-55332 | MED 6.1 | microsoft windows_10_1809 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2025-55330 | MED 6.1 | microsoft windows_11_22h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2025-32717 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-20209 | HIGH 7.5 | cisco ios_xr A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets. This vulnerability is due to | 0.5% | — |
| CVE-2025-20142 | HIGH 8.6 | cisco ios_xr A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Perf | 0.5% | — |