58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41033 | HIGH 7.8 | microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2023-28229 | HIGH 7.0 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2024-38107 | HIGH 7.8 | microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2025-24989 | HIGH 8.2 | microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust | 1.6% | |
| CVE-2026-33824 | CRIT 9.8 | microsoft windows_10_1607 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | 1.6% | |
| CVE-2021-41357 | HIGH 7.8 | microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2021-40450 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2026-21514 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | 1.6% | |
| CVE-2025-21418 | HIGH 7.8 | microsoft windows_10_1607 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2025-22224 | CRIT 9.3 | vmware cloud_foundation VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach | 1.6% | |
| CVE-2025-21334 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2021-36742 | HIGH 7.8 | trendmicro apex_one A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obta | 1.5% | |
| CVE-2019-1214 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. | 1.4% | |
| CVE-2025-32701 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 1.4% | |
| CVE-2025-21335 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.4% | |
| CVE-2025-24983 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 1.4% | |
| CVE-2024-53150 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, | 1.4% | |
| CVE-2026-88772 | HIGH 8.1 | citrix netscaler_application_delivery_controller Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote | 1.3% | |
| CVE-2024-49035 | HIGH 8.7 | microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | 1.3% | |
| CVE-2025-38352 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() | 1.3% | |
| CVE-2025-39964 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, | 1.3% | |
| CVE-2026-45498 | MED 4.0 | microsoft defender_antimalware_platform Microsoft Defender Denial of Service Vulnerability | 1.3% | |
| CVE-2023-36851 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph | 1.1% | |
| CVE-2026-76504 | CRIT 9.8 | cisco catalyst_sd-wan_manager A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handlin | 1.1% | |
| CVE-2026-88771 | CRIT 9.8 | citrix netscaler_application_delivery_controller Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13 | 1.1% |