58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-1826 | MED 6.2 | linux linux_kernel The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer derefere | 0.5% | — |
| CVE-2012-2273 | MED 4.9 | comodo comodo_internet_security Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel ImageBase value. | 0.5% | — |
| CVE-2011-2210 | LOW 2.1 | linux linux_kernel The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kernel mem | 0.5% | — |
| CVE-2026-67590 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue | 0.5% | — |
| CVE-2026-67589 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes | 0.5% | — |
| CVE-2026-56163 | CRIT 10.0 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-49268 | CRIT 9.1 | apache shiro A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. T | 0.5% | — |
| CVE-2026-48834 | HIGH 7.5 | apache answer Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessiv | 0.5% | — |
| CVE-2026-47280 | CRIT 10.0 | microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-42822 | CRIT 10.0 | microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-20811 | HIGH 7.8 | microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-17707 | MED 6.5 | google chrome Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severit | 0.5% | — |
| CVE-2025-48459 | MED 5.3 | apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | 0.5% | — |
| CVE-2025-47174 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-23335 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to d | 0.5% | — |
| CVE-2025-20386 | HIGH 8.0 | splunk splunk In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets n | 0.5% | — |
| CVE-2024-43115 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which | 0.5% | — |
| CVE-2023-35342 | HIGH 7.8 | microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35312 | HIGH 7.8 | microsoft windows_10_1507 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-2971 | MED 6.3 | typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo | 0.5% | — |
| CVE-2023-21755 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-20167 | MED 6.0 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabi | 0.5% | — |
| CVE-2022-44680 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44677 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35850 | MED 4.3 | fortinet fortiauthenticator An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected | 0.5% | — |