58.211 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.211 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20184 | MED 5.4 | cisco catalyst_center Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user | 0.5% | — |
| CVE-2023-28272 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-3643 | MED 6.5 | debian debian_linux Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest | 0.5% | — |
| CVE-2022-27503 | MED 6.1 | citrix storefront_server Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 | 0.5% | — |
| CVE-2022-27966 | MED 6.5 | netsarang xshell Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2022-27965 | MED 6.5 | netsarang xlpd Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2022-27964 | MED 6.5 | netsarang xmanager Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2021-42286 | HIGH 7.8 | microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42283 | HIGH 8.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41377 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41370 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41367 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41366 | HIGH 7.8 | microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36957 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-3564 | MED 5.5 | debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi | 0.5% | — |
| CVE-2020-5869 | CRIT 9.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. | 0.5% | — |
| CVE-2015-8569 | LOW 2.3 | linux linux_kernel The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism | 0.5% | — |
| CVE-2011-1182 | LOW 3.6 | linux linux_kernel kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. | 0.5% | — |
| CVE-2011-1023 | MED 4.9 | linux linux_kernel The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) tra | 0.5% | — |
| CVE-2009-1630 | MED 4.4 | canonical ubuntu_linux The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions | 0.5% | — |
| CVE-2003-1161 | HIGH 7.2 | linux linux_kernel exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function. | 0.5% | — |
| CVE-2026-58076 | HIGH 8.8 | apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's | 0.5% | — |
| CVE-2026-62915 | MED 6.5 | microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-61920 | MED 6.6 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-67588 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the | 0.5% | — |