58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-0322 | MED 4.9 | canonical ubuntu_linux drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in / | 0.5% | — |
| CVE-2005-3181 | LOW 2.1 | canonical ubuntu_linux The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak | 0.5% | — |
| CVE-2005-0001 | MED 6.9 | linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor | 0.5% | — |
| CVE-2026-33833 | HIGH 8.2 | microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-61624 | MED 6.0 | fortinet fortios An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPA | 0.5% | — |
| CVE-2025-60709 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-58087 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire. | 0.5% | — |
| CVE-2024-52969 | MED 4.1 | fortinet fortisiem An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 a | 0.5% | — |
| CVE-2024-43570 | MED 6.4 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-26013 | HIGH 7.5 | fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 | 0.5% | — |
| CVE-2024-22238 | MED 6.4 | vmware aria_operations_for_networks Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. | 0.5% | — |
| CVE-2024-20417 | MED 6.5 | cisco identity_services_engine Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST AP | 0.5% | — |
| CVE-2024-20310 | MED 6.1 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the inter | 0.5% | — |
| CVE-2023-27999 | HIGH 7.8 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | 0.5% | — |
| CVE-2023-21724 | HIGH 7.8 | microsoft windows_10_20h2 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41094 | HIGH 7.8 | microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-40454 | MED 5.5 | microsoft 365_apps Rich Text Edit Control Information Disclosure Vulnerability | 0.5% | — |
| CVE-2021-1131 | MED 6.5 | cisco video_surveillance_8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco | 0.5% | — |
| CVE-2018-0429 | HIGH 7.8 | cisco thor_video_codec Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream. | 0.5% | — |
| CVE-2017-4946 | HIGH 7.8 | vmware vrealize_operations_for_horizon The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. | 0.5% | — |
| CVE-2016-3699 | HIGH 7.4 | linux linux_kernel The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the init | 0.5% | — |
| CVE-2014-8989 | MED 4.6 | linux linux_kernel The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group categ | 0.5% | — |
| CVE-2014-4654 | MED 4.6 | canonical ubuntu_linux The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a de | 0.5% | — |
| CVE-2014-4653 | MED 4.6 | canonical ubuntu_linux sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memor | 0.5% | — |
| CVE-2009-2406 | MED 6.9 | linux kernel Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors invol | 0.5% | — |