IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-33211 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of this vulnerability may lead to denial of service. 0.7%
CVE-2024-56645 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() t 0.7%
CVE-2023-36701 HIGH 7.8 microsoft windows_10_1507 Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.7%
CVE-2023-24896 MED 5.4 microsoft dynamics_365 Dynamics 365 Finance Spoofing Vulnerability 0.7%
CVE-2022-26386 MED 6.5 mozilla firefox_esr Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was re 0.7%
CVE-2022-21871 HIGH 7.0 microsoft visual_studio_2017 Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability 0.7%
CVE-2019-15217 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver. 0.7%
CVE-2017-12341 MED 6.7 cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie 0.7%
CVE-2013-0248 LOW 3.3 apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. 0.7%
CVE-2012-4001 MED 5.0 google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. 0.7%
CVE-2026-85893 HIGH 8.8 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-52760 MED 6.1 apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic 0.7%
CVE-2025-21399 HIGH 7.4 microsoft edge_update Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability 0.7%
CVE-2024-47739 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock on seq_nr overflow When submitting more than 2^32 padata objects to padata_do_serial, the current sorting implementation incorrectly sorts 0.7%
CVE-2024-26665 CRIT 9.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x 0.7%
CVE-2023-52441 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_ 0.7%
CVE-2023-36760 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 0.7%
CVE-2023-36740 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 0.7%
CVE-2023-36739 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 0.7%
CVE-2022-49194 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Use stronger register read/writes to assure ordering GCC12 appears to be much smarter about its dependency tracking and is aware that the relaxed variants are just normal load 0.7%
CVE-2022-49048 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when forwarding a pkt with no in6 dev kongweibin reported a kernel panic in ip6_forward() when input interface has no in6 dev associated. The following tc commands were used 0.7%
CVE-2022-47984 MED 6.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. 0.7%
CVE-2022-30535 MED 6.5 f5 nginx_ingress_controller In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are no 0.7%
CVE-2022-2622 MED 6.5 fedoraproject fedora Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file. 0.7%
CVE-2019-19332 MED 6.1 linux linux_kernel An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or proc 0.7%