IT
58.628 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.628 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-3055 CRIT 9.8 citrix netscaler_application_delivery_controller Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread 4.0%
CVE-2024-26169 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 4.0%
CVE-2024-30040 HIGH 8.8 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 3.9%
CVE-2025-24985 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. 3.9%
CVE-2025-25249 HIGH 8.1 fortinet fortios A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7. 3.9%
CVE-2023-0266 HIGH 7.9 debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W 3.7%
CVE-2020-3566 HIGH 8.6 cisco ios_xr A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue managemen 3.7%
CVE-2026-85880 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2019-1385 HIGH 7.8 ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially craf 3.6%
CVE-2024-8068 HIGH 8.0 citrix session_recording Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain 3.5%
CVE-2019-1315 HIGH 7.8 ransomware microsoft windows_10_1607 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342. 3.5%
CVE-2018-0175 HIGH 8.0 cisco ios Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute 3.5%
CVE-2018-8406 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 3.4%
CVE-2018-8405 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Wind 3.4%
CVE-2026-31431 HIGH 7.8 amazon amazon_linux In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in alg 3.4%
CVE-2024-53104 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating 3.4%
CVE-2018-0167 HIGH 8.8 cisco ios Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio 3.4%
CVE-2020-3569 HIGH 8.6 cisco ios_xr Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it con 3.3%
CVE-2009-2055 MED 5.9 cisco ios_xr Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. 3.3%
CVE-2022-40139 HIGH 7.2 trendmicro apex_one Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, whi 3.3%
CVE-2013-2596 HIGH 7.8 linux linux_kernel Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel mem 3.2%
CVE-2023-6548 MED 5.5 citrix netscaler_application_delivery_controller Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf 3.2%
CVE-2017-0001 HIGH 7.8 microsoft windows_10_1507 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a 3.1%
CVE-2021-43226 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 3.1%
CVE-2023-36584 MED 5.4 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 3.1%