58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-20214 | MED 4.3 | cisco ios_xe A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a sub | 0.3% | — |
| CVE-2025-20180 | MED 4.8 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o | 0.3% | — |
| CVE-2024-47443 | HIGH 7.8 | adobe after_effects After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.3% | — |
| CVE-2024-47442 | HIGH 7.8 | adobe after_effects After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.3% | — |
| CVE-2024-47441 | HIGH 7.8 | adobe after_effects After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.3% | — |
| CVE-2024-41034 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug on rename operation of broken directory Syzbot reported that in rename directory operation on broken directory on nilfs2, __block_write_begin_int() called to prepare b | 0.3% | — |
| CVE-2024-35915 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet syzbot reported the following uninit-value access issue [1][2]: nci_rx_work() parses and processes received packet. When the payl | 0.3% | — |
| CVE-2021-38926 | MED 5.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321. | 0.3% | — |
| CVE-2020-1619 | MED 6.0 | juniper junos A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine (NG-RE), allows a local authenticated high privileged user to access the underlying WRL host. This issue only a | 0.3% | — |
| CVE-2013-4367 | HIGH 7.8 | ovirt ovirt-engine ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'. | 0.3% | — |
| CVE-2017-3166 | HIGH 7.8 | apache hadoop In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable locatio | 0.3% | — |
| CVE-2017-6666 | MED 6.0 | cisco ios_xr A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) | 0.3% | — |
| CVE-2017-2328 | MED 5.5 | juniper northstar_controller An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the Nort | 0.3% | — |
| CVE-2016-8981 | MED 5.5 | ibm bigfix_inventory IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. | 0.3% | — |
| CVE-2015-0584 | HIGH 7.2 | cisco desktop_collaboration_experience_dx650 The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka Bug ID CSCus38947. | 0.3% | — |
| CVE-2012-4206 | MED 6.9 | mozilla firefox Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory. | 0.3% | — |
| CVE-2026-46729 | HIGH 7.5 | apache http_server NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | 0.3% | — |
| CVE-2026-92608 | HIGH 7.5 | apache qpid_broker-j Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issu | 0.3% | — |
| CVE-2026-75698 | CRIT 9.3 | adobe connect Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Ex | 0.3% | — |
| CVE-2026-69534 | HIGH 7.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50523 | HIGH 7.8 | microsoft powershell Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68792 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65673 | HIGH 7.8 | microsoft entra_connect Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50488 | HIGH 7.8 | microsoft windows_11_24h2 Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |