IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-20865 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-20863 HIGH 7.0 microsoft windows_11_23h2 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-20842 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-20822 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59290 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-58716 HIGH 8.8 microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-58715 HIGH 8.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-38608 HIGH 8.6 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls When sending plaintext data, we initially calculated the corresponding ciphertext length. However, if we later reduced th 0.4% —
CVE-2024-20431 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation da 0.4% —
CVE-2024-30058 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4% —
CVE-2024-20361 MED 5.8 cisco secure_firewall_management_center A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Fire 0.4% —
CVE-2024-20293 MED 5.8 cisco adaptive_security_appliance_software A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by 0.4% —
CVE-2022-41738 HIGH 7.5 ibm spectrum_scale_container_native_storage_access IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. 0.4% —
CVE-2024-0007 MED 6.8 paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another 0.4% —
CVE-2023-25603 MED 5.4 fortinet fortiadc A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted 0.4% —
CVE-2023-32050 HIGH 7.0 microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability 0.4% —
CVE-2022-34242 HIGH 7.8 adobe character_animator Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage 0.4% —
CVE-2022-28388 MED 5.5 debian debian_linux usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. 0.4% —
CVE-2021-38160 HIGH 7.8 debian debian_linux In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vul 0.4% —
CVE-2020-18171 HIGH 8.8 techsmith snagit TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. 0.4% —
CVE-2021-1237 HIGH 7.8 cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker w 0.4% —
CVE-2020-36163 CRIT 9.3 veritas netbackup An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, 0.4% —
CVE-2020-3972 LOW 3.3 vmware tools VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest File System (HGFS) implementation. Successful exploitation of this issue may allow attackers with non-admin privileges on guest macOS virtual m 0.4% —
CVE-2019-0070 HIGH 8.8 juniper junos An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This l 0.4% —
CVE-2010-5331 HIGH 7.8 linux linux_kernel In the Linux kernel before 2.6.34, a range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (buffer overflow) problem. NOTE: At least one Linux maintainer believes that this CVE is incorrectly assigned and should be rejected because t 0.4% —