58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-1978 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069. | 0.5% | — |
| CVE-2016-7081 | HIGH 7.8 | vmware workstation_player Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS via | 0.5% | — |
| CVE-2014-9900 | MED 5.5 | google android The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via | 0.5% | — |
| CVE-2012-2490 | MED 5.0 | cisco ip_communicator Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471. | 0.5% | — |
| CVE-2012-2390 | MED 4.9 | linux linux_kernel Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations. | 0.5% | — |
| CVE-2005-0532 | LOW 2.1 | linux linux_kernel The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between s | 0.5% | — |
| CVE-2026-78449 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-72981 | HIGH 8.1 | microsoft windows_10_1607 Use after free in IP Helper allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-49845 | CRIT 9.8 | apache hive SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updat | 0.5% | — |
| CVE-2026-44822 | HIGH 8.2 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-22042 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context. | 0.5% | — |
| CVE-2025-20162 | HIGH 8.6 | cisco ios_xe A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to imp | 0.5% | — |
| CVE-2024-20426 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial | 0.5% | — |
| CVE-2023-42019 | MED 5.9 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161. | 0.5% | — |
| CVE-2023-36759 | MED 6.7 | microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-24965 | MED 5.8 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713. | 0.5% | — |
| CVE-2022-40277 | HIGH 7.8 | joplinapp joplin Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existin | 0.5% | — |
| CVE-2022-22442 | MED 6.5 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427." | 0.5% | — |
| CVE-2021-43076 | MED 6.3 | fortinet fortiadc An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system fil | 0.5% | — |
| CVE-2020-5032 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent particular payloads. IBM X-Force ID: 194178. | 0.5% | — |
| CVE-2020-29373 | MED 6.5 | linux linux_kernel An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d. | 0.5% | — |
| CVE-2019-6724 | HIGH 7.8 | barracuda vpn_client The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root. | 0.5% | — |
| CVE-2019-18895 | HIGH 7.8 | scanguard scanguard_antivirus Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file. | 0.5% | — |
| CVE-2019-15996 | MED 6.7 | cisco dna_spaces\ A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execut | 0.5% | — |
| CVE-2019-15628 | HIGH 7.8 | trendmicro antivirus_\+_security_2020 Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the s | 0.5% | — |