58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-1350 | MED 5.5 | linux linux_kernel The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed in | 0.5% | — |
| CVE-2013-4483 | MED 4.9 | linux linux_kernel The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application. | 0.5% | — |
| CVE-2012-4467 | MED 6.6 | linux linux_kernel The (1) do_siocgstamp and (2) do_siocgstampns functions in net/socket.c in the Linux kernel before 3.5.4 use an incorrect argument order, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) vi | 0.5% | — |
| CVE-2006-6058 | MED 4.0 | linux linux_kernel The minix filesystem code in Linux kernel 2.6.x before 2.6.24, including 2.6.18, allows local users to cause a denial of service (hang) via a malformed minix file stream that triggers an infinite loop in the minix_bmap function. NOTE: this issue might be due | 0.5% | — |
| CVE-2026-91866 | HIGH 7.5 | apache neethi A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | 0.5% | — |
| CVE-2026-91865 | HIGH 7.5 | apache neethi A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, w | 0.5% | — |
| CVE-2026-91864 | HIGH 7.5 | apache neethi A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4 | 0.5% | — |
| CVE-2026-80098 | CRIT 9.3 | microsoft copilot_studio Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-68287 | HIGH 7.5 | In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC a | 0.5% | — |
| CVE-2026-61634 | ND | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/Soc | 0.5% | — |
| CVE-2026-59878 | HIGH 7.5 | apache activemq Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause | 0.5% | — |
| CVE-2026-53395 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dead ACL conflict guard in nfsd4_create nfsd4_create() steals create->cr_dpacl/cr_pacl into the local nfsd_attrs via the designated initializer, then immediately sets the source po | 0.5% | — |
| CVE-2026-53244 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: VFS: fix possible failure to unlock in nfsd4_create_file() atomic_create() in fs/namei.c drops the reference to the dentry when it returns an error. This behaviour was imported into dentry_c | 0.5% | — |
| CVE-2026-53165 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iomap: avoid potential null folio->mapping deref during error reporting When a buffered read fails, iomap_finish_folio_read() reports the error with fserror_report_io(folio->mapping->host, . | 0.5% | — |
| CVE-2026-20839 | MED 5.5 | microsoft windows_10_1607 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-60012 | MED 6.3 | apache livy Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version | 0.5% | — |
| CVE-2025-54912 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-45642 | MED 5.3 | ibm security_qradar_edr IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted | 0.5% | — |
| CVE-2024-43585 | MED 5.5 | microsoft windows_10_1809 Code Integrity Guard Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-23665 | MED 5.9 | fortinet fortiweb Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM | 0.5% | — |
| CVE-2023-20266 | MED 6.5 | cisco emergency_responder A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to eleva | 0.5% | — |
| CVE-2022-45860 | MED 5.3 | fortinet fortinac A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform pa | 0.5% | — |
| CVE-2022-35798 | LOW 3.3 | microsoft azure_arc_jumpstart Azure Arc Jumpstart Information Disclosure Vulnerability | 0.5% | — |
| CVE-2021-29863 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerabilit | 0.5% | — |
| CVE-2020-9667 | MED 6.5 | adobe genuine_service Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An authenticated attacker with admin privileges could plant custom binaries and execute them with System permissions. Exploitation of this issue r | 0.5% | — |