58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-48716 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fix thi | 0.5% | — |
| CVE-2022-4744 | HIGH 7.8 | linux linux_kernel A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate thei | 0.5% | — |
| CVE-2020-4675 | MED 6.5 | ibm infosphere_master_data_management_server IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324. | 0.5% | — |
| CVE-2019-4057 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567. | 0.5% | — |
| CVE-2019-20810 | MED 5.5 | canonical ubuntu_linux go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586. | 0.5% | — |
| CVE-2018-8087 | MED 5.5 | canonical ubuntu_linux Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case. | 0.5% | — |
| CVE-2017-2618 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory. | 0.5% | — |
| CVE-2017-14187 | MED 6.2 | fortinet fortios A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via lin | 0.5% | — |
| CVE-2016-4922 | HIGH 8.4 | juniper junos Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevate | 0.5% | — |
| CVE-2016-2063 | HIGH 7.8 | linux linux_kernel Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, all | 0.5% | — |
| CVE-2015-3316 | MED 4.6 | broadcom network_and_systems_management CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infra | 0.5% | — |
| CVE-2013-2888 | MED 6.2 | linux linux_kernel Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a craf | 0.5% | — |
| CVE-2010-4242 | MED 4.0 | linux linux_kernel The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL po | 0.5% | — |
| CVE-2026-77102 | HIGH 7.5 | commvault commvault CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.5% | — |
| CVE-2026-77101 | HIGH 7.5 | commvault commvault CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.5% | — |
| CVE-2026-50419 | LOW 3.3 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50416 | LOW 3.3 | microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-3536 | HIGH 8.8 | google chrome Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-32327 | CRIT 9.1 | apache apr-util A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this | 0.5% | — |
| CVE-2026-32152 | HIGH 7.8 | microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-26112 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-20192 | CRIT 10.0 | cisco identity_services_engine As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review | 0.5% | — |
| CVE-2025-64407 | MED 5.3 | apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. Such links could also be used to transmit system inf | 0.5% | — |
| CVE-2025-59280 | LOW 3.1 | microsoft windows_10_1507 Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | 0.5% | — |
| CVE-2025-53845 | MED 6.5 | fortinet fortianalyzer An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via cr | 0.5% | — |