CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,540
Total CVEs
1,540
CISA KEV
1540
Critical & High
Mar 11, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2022-38181 | High | ArmMali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | Mar 30, 2023 | KEV |
| CVE-2022-3038 | High | GoogleChromium Network Service | Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Mar 30, 2023 | KEV |
| CVE-2013-3163 | High | MicrosoftInternet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. | Mar 30, 2023 | KEV |
| CVE-2021-30900 | High | AppleiOS, iPadOS, and macOS | Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. | Mar 30, 2023 | KEV |
| CVE-2023-0266 | High | LinuxKernel | Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. | Mar 30, 2023 | KEV |
| CVE-2022-22706 | High | ArmMali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. | Mar 30, 2023 | KEV |
| CVE-2023-26360 | High | AdobeColdFusion | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. | Mar 15, 2023 | KEV |
| CVE-2023-24880 | High | MicrosoftWindows | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Mar 14, 2023 | KEV |
| CVE-2023-23397 | High | MicrosoftOffice | Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. | Mar 14, 2023 | KEV |
| CVE-2022-41328 | High | FortinetFortiOS | Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. | Mar 14, 2023 | KEV |
| CVE-2020-5741 | High | PlexMedia Server | Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. | Mar 10, 2023 | KEV |
| CVE-2021-39144 | High | XStreamXStream | XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. | Mar 10, 2023 | KEV |
| CVE-2022-28810 | High | ZohoManageEngine | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. | Mar 7, 2023 | KEV |
| CVE-2022-33891 | High | ApacheSpark | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. | Mar 7, 2023 | KEV |
| CVE-2022-35914 | High | TeclibGLPI | Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. | Mar 7, 2023 | KEV |
| CVE-2022-36537 | High | ZK FrameworkAuUploader | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. | Feb 27, 2023 | KEV |
| CVE-2022-47986 | High | IBMAspera Faspex | IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. | Feb 21, 2023 | KEV |
| CVE-2022-41223 | High | MitelMiVoice Connect | The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. | Feb 21, 2023 | KEV |
| CVE-2022-40765 | High | MitelMiVoice Connect | The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. | Feb 21, 2023 | KEV |
| CVE-2022-46169 | High | CactiCacti | Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. | Feb 16, 2023 | KEV |