IT
58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-53723 HIGH 7.8 microsoft windows_10_1507 Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-53155 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-32703 MED 5.5 microsoft visual_studio_2017 Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. 0.5% —
CVE-2024-53090 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to take a ref on the 0.5% —
CVE-2024-32761 MED 6.5 f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of 0.5% —
CVE-2023-38106 LOW 3.3 foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this 0.5% —
CVE-2023-38105 LOW 3.3 foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this 0.5% —
CVE-2023-38046 MED 5.5 paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. 0.5% —
CVE-2023-28276 MED 4.4 microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability 0.5% —
CVE-2022-22944 MED 5.4 vmware workspace_one_boxer VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary scr 0.5% —
CVE-2014-9584 LOW 2.1 canonical ubuntu_linux The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory vi 0.5% —
CVE-2014-7975 MED 5.5 canonical ubuntu_linux The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writabi 0.5% —
CVE-2013-7265 MED 4.9 linux linux_kernel The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack 0.5% —
CVE-2013-7263 MED 4.9 linux linux_kernel The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvm 0.5% —
CVE-2013-0914 LOW 3.6 linux linux_kernel The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted applicatio 0.5% —
CVE-2010-3881 LOW 2.1 linux linux_kernel arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device. 0.5% —
CVE-2003-0984 MED 4.6 linux linux_kernel Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space. 0.5% —
CVE-2026-59289 HIGH 7.5 vmware spring_for_graphql Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memor 0.5% —
CVE-2026-59282 HIGH 7.5 vmware spring_framework Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring 0.5% —
CVE-2026-57026 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is e 0.5% —
CVE-2026-57023 HIGH 7.5 juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When 0.5% —
CVE-2026-47886 HIGH 7.5 vmware spring_framework Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framewor 0.5% —
CVE-2026-31910 HIGH 7.5 apache ofbiz Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.5% —
CVE-2026-25168 MED 6.2 microsoft windows_10_1607 Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. 0.5% —
CVE-2025-61974 HIGH 7.5 f5 big-ip_next_cloud-native_network_functions When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5% —