57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-33840 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2025-68675 | HIGH 7.5 | apache airflow In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatical | 2.0% | — |
| CVE-2025-49220 | CRIT 9.8 | trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | 2.0% | — |
| CVE-2022-42896 | HIGH 8.0 | linux linux_kernel There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could | 2.0% | — |
| CVE-2019-19449 | HIGH 7.8 | linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry | 2.0% | — |
| CVE-2019-1442 | MED 5.5 | microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab | 2.0% | — |
| CVE-2013-0681 | MED 5.0 | cogentdatahub cascade_datahub Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) | 2.0% | — |
| CVE-2020-1195 | LOW 3.1 | microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privi | 2.0% | — |
| CVE-2016-9249 | HIGH 7.5 | f5 big-ip_access_policy_manager An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS). | 2.0% | — |
| CVE-2016-6462 | MED 5.3 | cisco email_security_appliance_firmware A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. T | 2.0% | — |
| CVE-2021-40784 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir | 2.0% | — |
| CVE-2021-40783 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir | 2.0% | — |
| CVE-2009-5040 | MED 6.8 | cisco ios CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555. | 2.0% | — |
| CVE-2022-24460 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-43016 | MED 5.5 | adobe incopy Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t | 2.0% | — |
| CVE-2010-0139 | HIGH 9.0 | cisco unified_meetingplace Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691. | 2.0% | — |
| CVE-2024-43609 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 2.0% | — |
| CVE-2023-36567 | HIGH 7.5 | microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-29348 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-21757 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-30145 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2018-15444 | MED 6.3 | cisco energy_management_suite_software A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand | 2.0% | — |
| CVE-2013-5557 | MED 6.3 | cisco adaptive_security_appliance_software The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request | 2.0% | — |
| CVE-2004-0710 | MED 5.0 | cisco ios IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (devi | 2.0% | — |
| CVE-2022-37976 | HIGH 8.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2.0% | — |