IT
58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-41033 HIGH 7.8 microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability 1.7%
CVE-2023-28229 HIGH 7.0 microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 1.7%
CVE-2024-38107 HIGH 7.8 microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability 1.6%
CVE-2025-24989 HIGH 8.2 microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust 1.6%
CVE-2026-33824 CRIT 9.8 microsoft windows_10_1607 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. 1.6%
CVE-2021-41357 HIGH 7.8 microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability 1.6%
CVE-2021-40450 HIGH 7.8 microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability 1.6%
CVE-2026-21514 HIGH 7.8 microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. 1.6%
CVE-2025-21418 HIGH 7.8 microsoft windows_10_1607 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 1.6%
CVE-2025-22224 CRIT 9.3 vmware cloud_foundation VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach 1.6%
CVE-2025-21334 HIGH 7.8 microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability 1.6%
CVE-2021-36742 HIGH 7.8 trendmicro apex_one A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obta 1.5%
CVE-2019-1214 HIGH 7.8 microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. 1.4%
CVE-2025-32701 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 1.4%
CVE-2025-21335 HIGH 7.8 microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability 1.4%
CVE-2025-24983 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 1.4%
CVE-2024-53150 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, 1.4%
CVE-2026-88772 HIGH 8.1 citrix netscaler_application_delivery_controller Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote 1.3%
CVE-2024-49035 HIGH 8.7 microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. 1.3%
CVE-2025-38352 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() 1.3%
CVE-2025-39964 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, 1.3%
CVE-2026-45498 MED 4.0 microsoft defender_antimalware_platform Microsoft Defender Denial of Service Vulnerability 1.3%
CVE-2023-36851 MED 5.3 juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph 1.1%
CVE-2026-76504 CRIT 9.8 cisco catalyst_sd-wan_manager A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handlin 1.1%
CVE-2026-88771 CRIT 9.8 citrix netscaler_application_delivery_controller Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13 1.1%