58.202 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.202 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37984 | HIGH 7.8 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-37983 | HIGH 7.8 | microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-29888 | HIGH 8.8 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123. | 0.5% | — |
| CVE-2021-3049 | LOW 2.6 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part | 0.5% | — |
| CVE-2018-0053 | MED 6.8 | juniper junos An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Junipe | 0.5% | — |
| CVE-2018-15431 | HIGH 7.3 | cisco webex_business_suite_32 A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 0.5% | — |
| CVE-2018-5750 | MED 5.5 | canonical ubuntu_linux The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call. | 0.5% | — |
| CVE-2004-0394 | LOW 2.1 | linux linux_kernel A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic. | 0.5% | — |
| CVE-2026-65092 | HIGH 8.5 | nvidia openshell NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | 0.5% | — |
| CVE-2026-17692 | CRIT 9.6 | google chrome Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-57095 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-13794 | HIGH 7.5 | google chrome Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium securi | 0.5% | — |
| CVE-2026-49298 | HIGH 8.8 | apache airflow A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes re | 0.5% | — |
| CVE-2026-40976 | CRIT 9.1 | vmware spring_boot In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and re | 0.5% | — |
| CVE-2026-27931 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-20174 | MED 4.9 | cisco nexus_dashboard A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. | 0.5% | — |
| CVE-2026-23111 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nf | 0.5% | — |
| CVE-2025-53800 | HIGH 7.8 | microsoft windows_10_1607 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-38181 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). syzkaller reported a null-ptr-deref in sock_omalloc() while allocating a CALIPSO option. [0] The NULL is of struct sock, which w | 0.5% | — |
| CVE-2025-21788 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases If the XDP program doesn't result in XDP_PASS then we leak the memory allocated by am65_cpsw_build_skb(). It is pointless to a | 0.5% | — |
| CVE-2024-20526 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a logic | 0.5% | — |
| CVE-2024-20342 | MED 5.8 | cisco secure_firewall_threat_defense Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incor | 0.5% | — |
| CVE-2021-47467 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kunit: fix reference count leak in kfree_at_end The reference counting issue happens in the normal path of kfree_at_end(). When kunit_alloc_and_get_resource() is invoked, the function forget | 0.5% | — |
| CVE-2022-28835 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 0.5% | — |
| CVE-2021-42734 | MED 5.5 | adobe photoshop Adobe Photoshop version 22.5.1 and earlier versions are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0.5% | — |