IT
58.318 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.318 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-4739 HIGH 7.8 ibm db2 IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order 0.5% —
CVE-2019-12380 MED 5.5 linux linux_kernel **DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: 0.5% —
CVE-2017-18216 MED 5.5 linux linux_kernel In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users can cause a denial of service (NULL pointer dereference and BUG) because a required mutex is not used. 0.5% —
CVE-2017-14140 MED 5.5 linux linux_kernel The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR. 0.5% —
CVE-2010-2071 MED 4.6 linux linux_kernel The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl 0.5% —
CVE-2010-1558 MED 4.7 hp multifunction_peripheral_digital_sending_software Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors. 0.5% —
CVE-2006-5751 HIGH 7.2 linux linux_kernel Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request. 0.5% —
CVE-2005-4639 MED 4.6 linux linux_kernel Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an 0.5% —
CVE-2026-78508 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-78452 MED 4.6 microsoft windows_10_1809 Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-69548 MED 4.6 microsoft windows_10_1607 Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-66842 HIGH 8.8 BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacke 0.5% —
CVE-2026-64281 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes Threads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or sc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state across transp 0.5% —
CVE-2026-62720 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-62716 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-62714 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-49794 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-47898 CRIT 9.8 apache lucene.net Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade 0.5% —
CVE-2025-62449 MED 6.8 microsoft github_copilot_chat Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. 0.5% —
CVE-2025-49743 MED 6.7 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-38018 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when alloc_page failed We cannot set frag_list to NULL pointer when alloc_page failed. It will be used in tls_strp_check_queue_ok when the next time tls_strp_read_s 0.5% —
CVE-2024-28905 HIGH 7.8 microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.5% —
CVE-2024-20469 MED 6.0 cisco identity_services_engine A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, 0.5% —
CVE-2023-4550 HIGH 7.5 opentext appbuilder Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on 0.5% —
CVE-2023-24930 HIGH 7.8 microsoft onedrive Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability 0.5% —