IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2010-4565 LOW 2.1 linux linux_kernel The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows 0.5% —
CVE-2026-81352 HIGH 8.8 microsoft web_media_extensions Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-69406 MED 5.5 microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-68786 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5% —
CVE-2026-68775 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5% —
CVE-2026-67642 HIGH 8.8 microsoft sql_server_2025 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5% —
CVE-2026-64430 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardirq context ntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive the vector number. pci_irq_vector() calls msi_get_virq() t 0.5% —
CVE-2026-59354 CRIT 9.6 vmware spring_security In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the regist 0.5% —
CVE-2026-46024 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treat 0.5% —
CVE-2026-43405 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Cur 0.5% —
CVE-2026-43099 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe() ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the IPv6 stack is not active (CONFIG_IPV6=m and not loaded), and passin 0.5% —
CVE-2026-40564 MED 6.5 apache flink_kubernetes_operator Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a u 0.5% —
CVE-2026-26110 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-23240 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can 0.5% —
CVE-2026-20005 MED 5.8 cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil 0.5% —
CVE-2025-53689 HIGH 8.8 apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja 0.5% —
CVE-2025-49751 MED 6.8 microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. 0.5% —
CVE-2025-36048 HIGH 7.2 ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. 0.5% —
CVE-2023-38733 MED 4.3 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. 0.5% —
CVE-2023-32553 MED 5.3 trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. 0.5% —
CVE-2022-38016 HIGH 8.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5% —
CVE-2022-37984 HIGH 7.8 microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability 0.5% —
CVE-2022-37983 HIGH 7.8 microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5% —
CVE-2021-47041 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix incorrect locking in state_change sk callback We are not changing anything in the TCP connection state so we should not take a write_lock but rather a read lock. This caused 0.5% —
CVE-2021-3049 LOW 2.6 paloaltonetworks cortex_xsoar An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part 0.5% —