58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-38638 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38630 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38628 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38626 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38625 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36954 | HIGH 8.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2020-5917 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure. | 0.5% | — |
| CVE-2020-5870 | HIGH 8.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. | 0.5% | — |
| CVE-2019-4640 | CRIT 9.8 | ibm security_secret_server IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046. | 0.5% | — |
| CVE-2018-10902 | HIGH 7.8 | canonical ubuntu_linux It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. | 0.5% | — |
| CVE-2017-8360 | MED 5.5 | conexant mictray64 Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This da | 0.5% | — |
| CVE-2016-2543 | MED 6.2 | linux linux_kernel The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference an | 0.5% | — |
| CVE-2001-0020 | LOW 2.1 | cisco arrowpoint Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | 0.5% | — |
| CVE-2026-69775 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69761 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69340 | HIGH 7.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-68893 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-68835 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-68979 | CRIT 9.8 | apache nifi Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing compo | 0.5% | — |
| CVE-2026-62391 | HIGH 8.1 | apache kyuubi The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache | 0.5% | — |
| CVE-2026-45583 | HIGH 7.5 | microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 0.5% | — |