IT
58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-42990 HIGH 8.8 flexihub flexihub FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) 0.5% —
CVE-2021-40121 MED 6.1 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabili 0.5% —
CVE-2019-7487 HIGH 7.8 sonicwall sonicos Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution. 0.5% —
CVE-2019-12709 MED 6.7 cisco ios_xr A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux ope 0.5% —
CVE-2017-11742 HIGH 7.8 libexpat_project libexpat The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacki 0.5% —
CVE-2017-10911 MED 6.5 linux linux_kernel The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields i 0.5% —
CVE-2011-2534 HIGH 7.8 linux linux_kernel Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string 0.5% —
CVE-2011-2209 LOW 2.1 linux linux_kernel Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call. 0.5% —
CVE-2008-4917 HIGH 7.2 vmware esx Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allow 0.5% —
CVE-2008-2098 MED 6.9 vmware ace_2 Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sh 0.5% —
CVE-2006-6128 LOW 2.1 linux linux_kernel The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed. 0.5% —
CVE-2002-1963 LOW 2.1 linux linux_kernel Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries. 0.5% —
CVE-2026-71300 CRIT 9.8 apache camel Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects which 0.5% —
CVE-2026-64122 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover mlx5e_tx_reporter_timeout_recover() accesses sq->netdev after mlx5e_safe_reopen_channels() has torn down and freed the chan 0.5% —
CVE-2026-56161 CRIT 9.6 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. 0.5% —
CVE-2026-54988 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2026-44801 HIGH 7.5 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-44799 HIGH 7.5 microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-42992 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-34483 HIGH 7.5 apache tomcat Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended t 0.5% —
CVE-2026-34329 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. 0.5% —
CVE-2025-62465 MED 6.5 microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-62463 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-60708 MED 6.5 microsoft windows_10_1607 Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-59355 MED 6.5 apache linkis A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive informat 0.5% —