IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-33840 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2025-68675 HIGH 7.5 apache airflow In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatical 2.0%
CVE-2025-49220 CRIT 9.8 trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. 2.0%
CVE-2022-42896 HIGH 8.0 linux linux_kernel There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could 2.0%
CVE-2019-19449 HIGH 7.8 linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry 2.0%
CVE-2019-1442 MED 5.5 microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab 2.0%
CVE-2013-0681 MED 5.0 cogentdatahub cascade_datahub Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) 2.0%
CVE-2020-1195 LOW 3.1 microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privi 2.0%
CVE-2016-9249 HIGH 7.5 f5 big-ip_access_policy_manager An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS). 2.0%
CVE-2016-6462 MED 5.3 cisco email_security_appliance_firmware A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. T 2.0%
CVE-2021-40784 HIGH 7.8 adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir 2.0%
CVE-2021-40783 HIGH 7.8 adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir 2.0%
CVE-2009-5040 MED 6.8 cisco ios CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555. 2.0%
CVE-2022-24460 HIGH 7.0 microsoft windows_10 Tablet Windows User Interface Application Elevation of Privilege Vulnerability 2.0%
CVE-2021-43016 MED 5.5 adobe incopy Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t 2.0%
CVE-2010-0139 HIGH 9.0 cisco unified_meetingplace Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691. 2.0%
CVE-2024-43609 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 2.0%
CVE-2023-36567 HIGH 7.5 microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability 2.0%
CVE-2023-29348 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability 2.0%
CVE-2023-21757 HIGH 7.5 microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability 2.0%
CVE-2022-30145 HIGH 7.5 microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability 2.0%
CVE-2018-15444 MED 6.3 cisco energy_management_suite_software A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand 2.0%
CVE-2013-5557 MED 6.3 cisco adaptive_security_appliance_software The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request 2.0%
CVE-2004-0710 MED 5.0 cisco ios IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (devi 2.0%
CVE-2022-37976 HIGH 8.8 microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability 2.0%