IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2009-0322 MED 4.9 canonical ubuntu_linux drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in / 0.5% —
CVE-2005-3181 LOW 2.1 canonical ubuntu_linux The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak 0.5% —
CVE-2005-0001 MED 6.9 linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor 0.5% —
CVE-2026-33833 HIGH 8.2 microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. 0.5% —
CVE-2025-61624 MED 6.0 fortinet fortios An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPA 0.5% —
CVE-2025-60709 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2024-58087 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire. 0.5% —
CVE-2024-52969 MED 4.1 fortinet fortisiem An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 a 0.5% —
CVE-2024-43570 MED 6.4 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5% —
CVE-2024-26013 HIGH 7.5 fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 0.5% —
CVE-2024-22238 MED 6.4 vmware aria_operations_for_networks Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. 0.5% —
CVE-2024-20417 MED 6.5 cisco identity_services_engine Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST AP 0.5% —
CVE-2024-20310 MED 6.1 cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the inter 0.5% —
CVE-2023-27999 HIGH 7.8 fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. 0.5% —
CVE-2023-21724 HIGH 7.8 microsoft windows_10_20h2 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5% —
CVE-2022-41094 HIGH 7.8 microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability 0.5% —
CVE-2021-40454 MED 5.5 microsoft 365_apps Rich Text Edit Control Information Disclosure Vulnerability 0.5% —
CVE-2021-1131 MED 6.5 cisco video_surveillance_8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco 0.5% —
CVE-2018-0429 HIGH 7.8 cisco thor_video_codec Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream. 0.5% —
CVE-2017-4946 HIGH 7.8 vmware vrealize_operations_for_horizon The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. 0.5% —
CVE-2016-3699 HIGH 7.4 linux linux_kernel The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the init 0.5% —
CVE-2014-8989 MED 4.6 linux linux_kernel The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group categ 0.5% —
CVE-2014-4654 MED 4.6 canonical ubuntu_linux The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a de 0.5% —
CVE-2014-4653 MED 4.6 canonical ubuntu_linux sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memor 0.5% —
CVE-2009-2406 MED 6.9 linux kernel Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors invol 0.5% —