58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42990 | HIGH 8.8 | flexihub flexihub FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) | 0.5% | — |
| CVE-2021-40121 | MED 6.1 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabili | 0.5% | — |
| CVE-2019-7487 | HIGH 7.8 | sonicwall sonicos Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution. | 0.5% | — |
| CVE-2019-12709 | MED 6.7 | cisco ios_xr A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux ope | 0.5% | — |
| CVE-2017-11742 | HIGH 7.8 | libexpat_project libexpat The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacki | 0.5% | — |
| CVE-2017-10911 | MED 6.5 | linux linux_kernel The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields i | 0.5% | — |
| CVE-2011-2534 | HIGH 7.8 | linux linux_kernel Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string | 0.5% | — |
| CVE-2011-2209 | LOW 2.1 | linux linux_kernel Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call. | 0.5% | — |
| CVE-2008-4917 | HIGH 7.2 | vmware esx Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allow | 0.5% | — |
| CVE-2008-2098 | MED 6.9 | vmware ace_2 Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sh | 0.5% | — |
| CVE-2006-6128 | LOW 2.1 | linux linux_kernel The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed. | 0.5% | — |
| CVE-2002-1963 | LOW 2.1 | linux linux_kernel Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries. | 0.5% | — |
| CVE-2026-71300 | CRIT 9.8 | apache camel Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects which | 0.5% | — |
| CVE-2026-64122 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover mlx5e_tx_reporter_timeout_recover() accesses sq->netdev after mlx5e_safe_reopen_channels() has torn down and freed the chan | 0.5% | — |
| CVE-2026-56161 | CRIT 9.6 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-54988 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-44801 | HIGH 7.5 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-44799 | HIGH 7.5 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-42992 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-34483 | HIGH 7.5 | apache tomcat Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended t | 0.5% | — |
| CVE-2026-34329 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2025-62465 | MED 6.5 | microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-62463 | MED 6.5 | microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-60708 | MED 6.5 | microsoft windows_10_1607 Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-59355 | MED 6.5 | apache linkis A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive informat | 0.5% | — |