IT
58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-55679 MED 5.1 microsoft windows_10_1809 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2021-47290 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix NULL dereference on XCOPY completion CPU affinity control added with commit 39ae3edda325 ("scsi: target: core: Make completion affinity configurable") makes target_complete 0.5% —
CVE-2021-35477 MED 5.5 debian debian_linux In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operat 0.5% —
CVE-2020-29534 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimize unshare_fd(), aka CID-0f2122045b94. 0.5% —
CVE-2019-19533 LOW 2.4 linux linux_kernel In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464. 0.5% —
CVE-2019-19462 MED 5.5 canonical ubuntu_linux relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result. 0.5% —
CVE-2004-2607 LOW 2.1 linux linux_kernel A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop fro 0.5% —
CVE-2026-76427 MED 4.9 cisco identity_services_engine A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with 0.5% —
CVE-2026-70468 HIGH 8.1 fortinet fortimanager A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7. 0.5% —
CVE-2026-63530 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2026-50645 HIGH 7.5 apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 0.5% —
CVE-2026-42972 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-42971 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-3482 MED 5.3 ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially cr 0.5% —
CVE-2026-31669 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU read-side cr 0.5% —
CVE-2026-31649 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len = skb_headlen(skb) (line 0.5% —
CVE-2025-54941 MED 4.6 apache airflow An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the exa 0.5% —
CVE-2025-48840 MED 5.3 fortinet fortiweb An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a sp 0.5% —
CVE-2025-3500 CRIT 9.0 avast antivirus Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. 0.5% —
CVE-2025-22021 CRIT 10.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT nf_sk_lookup_slow_v4 does the conntrack lookup for IPv4 packets to restore the original 5-tuple in case of SNAT, to be able to find the rig 0.5% —
CVE-2024-9120 HIGH 8.8 google chrome Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.5% —
CVE-2023-21767 HIGH 7.8 microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability 0.5% —
CVE-2023-21754 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.5% —
CVE-2023-21558 HIGH 7.8 microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.5% —
CVE-2023-20265 MED 5.5 cisco ip_dect_110_firmware A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerabi 0.5% —