IT
57.638 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.638 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2010-3848 MED 6.9 canonical ubuntu_linux Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures. 0.7%
CVE-2007-1743 MED 4.4 apache http_server suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researche 0.7%
CVE-2001-1534 LOW 2.1 apache http_server mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's a 0.7%
CVE-1999-1441 LOW 2.1 linux linux_kernel Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it. 0.7%
CVE-2026-69826 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-69773 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-69727 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-69332 HIGH 8.0 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-58597 MED 4.3 microsoft edge_chromium Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2025-49713 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2024-39726 HIGH 8.2 ibm engineering_lifecycle_optimization_-_engineering_insights IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume 0.7%
CVE-2023-49250 HIGH 7.3 apache dolphinscheduler Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommen 0.7%
CVE-2022-44704 HIGH 7.8 microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability 0.7%
CVE-2022-44648 MED 5.5 trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged 0.7%
CVE-2022-44647 MED 5.5 trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged 0.7%
CVE-2022-21836 HIGH 7.8 microsoft windows_10 Windows Certificate Spoofing Vulnerability 0.7%
CVE-2022-20811 MED 5.5 cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a 0.7%
CVE-2021-31916 MED 6.7 debian debian_linux An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access t 0.7%
CVE-2021-29701 MED 4.3 ibm engineering_workflow_management IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. 0.7%
CVE-2021-1490 MED 4.7 cisco web_security_appliance A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. 0.7%
CVE-2021-0219 MED 6.7 juniper junos A command injection vulnerability in install package validation subsystem of Juniper Networks Junos OS that may allow a locally authenticated attacker with privileges to execute commands with root privilege. To validate a package in Junos before installation, 0.7%
CVE-2017-3196 HIGH 7.8 rawether_project rawether PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets. Local attackers can exploit this issue to execute 0.7%
CVE-2017-1677 HIGH 7.4 ibm db2 IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-F 0.7%
CVE-2012-5458 HIGH 8.3 vmware player VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application. 0.7%
CVE-2026-67368 HIGH 8.8 microsoft sql_server_2017 Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.7%