IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-28460 HIGH 8.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 0.5% —
CVE-2021-24012 MED 6.5 fortinet fortios An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority. 0.5% —
CVE-2020-4363 HIGH 7.8 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privil 0.5% —
CVE-2019-20406 HIGH 7.8 atlassian confluence The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental 0.5% —
CVE-2017-8924 MED 4.6 debian debian_linux The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as 0.5% —
CVE-2017-17558 MED 6.6 linux linux_kernel The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local us 0.5% —
CVE-2016-4805 HIGH 7.8 canonical ubuntu_linux Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network nam 0.5% —
CVE-2015-1333 MED 4.9 linux linux_kernel Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys. 0.5% —
CVE-2013-7281 MED 4.9 linux linux_kernel The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel 0.5% —
CVE-2013-7271 MED 4.9 linux linux_kernel The x25_recvmsg function in net/x25/af_x25.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory v 0.5% —
CVE-2013-7270 MED 4.9 linux linux_kernel The packet_recvmsg function in net/packet/af_packet.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel 0.5% —
CVE-2013-1827 MED 6.2 linux linux_kernel net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call. 0.5% —
CVE-2012-5374 MED 4.0 linux linux_kernel The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value. 0.5% —
CVE-2012-2053 HIGH 7.2 f5 firepass The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program, as demonstrated by the user account th 0.5% —
CVE-2010-3086 MED 4.9 linux linux_kernel include/asm-x86/futex.h in the Linux kernel before 2.6.25 does not properly implement exception fixup, which allows local users to cause a denial of service (panic) via an invalid application that triggers a page fault. 0.5% —
CVE-2026-73008 MED 5.5 microsoft windows_10_1607 Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-69862 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-69351 MED 5.5 microsoft windows_10_1607 Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-69339 MED 5.5 microsoft windows_11_24h2 Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-69315 MED 5.5 microsoft windows_10_1809 Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-69294 MED 5.5 microsoft windows_10_1809 Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-68886 MED 5.5 microsoft windows_10_1607 Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-68873 MED 5.5 microsoft windows_11_23h2 Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-68842 MED 5.5 microsoft windows_11_24h2 Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-64393 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after checking the access mask granted to the SMB handle. Those helpers perform their owner, in 0.5% —