IT
58.628 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.628 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-41125 HIGH 7.8 microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 3.0%
CVE-2026-50522 CRIT 9.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. 3.0%
CVE-2018-8589 HIGH 7.8 microsoft windows_7 An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. 3.0%
CVE-2021-31199 MED 5.2 microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability 3.0%
CVE-2024-7262 HIGH 7.8 kingsoft wps_office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click 2.9%
CVE-2021-38649 HIGH 7.0 microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability 2.9%
CVE-2025-39682 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next recor 2.9%
CVE-2021-38645 HIGH 7.8 microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability 2.7%
CVE-2026-45659 HIGH 8.8 ransomware microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.7%
CVE-2024-36971 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first 2.7%
CVE-2020-0878 MED 4.2 ransomware microsoft chakracore <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker 2.7%
CVE-2024-38226 HIGH 7.3 microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability 2.7%
CVE-2020-24557 HIGH 7.8 trendmicro apex_one A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e 2.7%
CVE-2025-59230 HIGH 7.8 microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 2.7%
CVE-2021-31201 MED 5.2 microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability 2.6%
CVE-2026-59310 CRIT 9.8 ransomware vmware vcenter_server VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. 2.6%
CVE-2022-0028 HIGH 8.6 paloaltonetworks pan-os A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir 2.5%
CVE-2025-62221 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 2.5%
CVE-2022-41049 MED 5.4 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 2.5%
CVE-2023-20109 MED 6.6 cisco ios A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitr 2.5%
CVE-2026-21519 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 2.5%
CVE-2026-11645 HIGH 8.8 google chrome Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 2.4%
CVE-2022-21919 HIGH 7.0 microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability 2.4%
CVE-2020-0638 HIGH 7.8 ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege 2.4%
CVE-2025-32706 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 2.3%