IT
58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-48716 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fix thi 0.5% —
CVE-2022-4744 HIGH 7.8 linux linux_kernel A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate thei 0.5% —
CVE-2020-4675 MED 6.5 ibm infosphere_master_data_management_server IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324. 0.5% —
CVE-2019-4057 MED 6.7 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567. 0.5% —
CVE-2019-20810 MED 5.5 canonical ubuntu_linux go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586. 0.5% —
CVE-2018-8087 MED 5.5 canonical ubuntu_linux Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case. 0.5% —
CVE-2017-2618 MED 5.5 debian debian_linux A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory. 0.5% —
CVE-2017-14187 MED 6.2 fortinet fortios A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via lin 0.5% —
CVE-2016-4922 HIGH 8.4 juniper junos Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevate 0.5% —
CVE-2016-2063 HIGH 7.8 linux linux_kernel Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, all 0.5% —
CVE-2015-3316 MED 4.6 broadcom network_and_systems_management CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infra 0.5% —
CVE-2013-2888 MED 6.2 linux linux_kernel Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a craf 0.5% —
CVE-2010-4242 MED 4.0 linux linux_kernel The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL po 0.5% —
CVE-2026-77102 HIGH 7.5 commvault commvault CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. 0.5% —
CVE-2026-77101 HIGH 7.5 commvault commvault CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. 0.5% —
CVE-2026-50419 LOW 3.3 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50416 LOW 3.3 microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-3536 HIGH 8.8 google chrome Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) 0.5% —
CVE-2026-32327 CRIT 9.1 apache apr-util A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this 0.5% —
CVE-2026-32152 HIGH 7.8 microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2026-26112 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-20192 CRIT 10.0 cisco identity_services_engine As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review 0.5% —
CVE-2025-64407 MED 5.3 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. Such links could also be used to transmit system inf 0.5% —
CVE-2025-59280 LOW 3.1 microsoft windows_10_1507 Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. 0.5% —
CVE-2025-53845 MED 6.5 fortinet fortianalyzer An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via cr 0.5% —