58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-24880 | HIGH 7.5 | apache tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 throug | 0.5% | — |
| CVE-2025-48418 | MED 6.7 | fortinet fortianalyzer A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnaly | 0.5% | — |
| CVE-2025-62555 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2024-20502 | MED 5.8 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insuffici | 0.5% | — |
| CVE-2024-21439 | HIGH 7.0 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-39191 | HIGH 8.2 | fedoraproject fedora An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF p | 0.5% | — |
| CVE-2023-35353 | HIGH 7.8 | microsoft windows_10_1607 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35326 | MED 5.5 | microsoft windows_10_1809 Windows CDP User Components Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-35324 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-35306 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-32085 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-32040 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2023-32039 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-41077 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28547 | HIGH 7.8 | adobe creative_cloud_desktop_application Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority. | 0.5% | — |
| CVE-2020-3969 | HIGH 7.8 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A ma | 0.5% | — |
| CVE-2019-5676 | MED 6.7 | nvidia geforce_experience NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to esc | 0.5% | — |
| CVE-2019-1800 | MED 6.5 | cisco wireless_lan_controller A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the s | 0.5% | — |
| CVE-2018-10901 | HIGH 7.8 | linux linux_kernel A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries i | 0.5% | — |
| CVE-2017-9490 | HIGH 8.8 | arris tg1682g_firmware The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF. | 0.5% | — |
| CVE-2015-6937 | MED 4.9 | canonical ubuntu_linux The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not proper | 0.5% | — |
| CVE-2012-1146 | MED 5.5 | fedoraproject fedora The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference | 0.5% | — |
| CVE-2009-2584 | HIGH 7.2 | linux linux_kernel Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via | 0.5% | — |
| CVE-2026-62781 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2023-53116 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid potential UAF in nvmet_req_complete() An nvme target ->queue_response() operation implementation may free the request passed as argument. Such implementation potentially could r | 0.5% | — |