58.450 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-3498 | MED 5.6 | citrix xenserver PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index. | 0.4% | — |
| CVE-2012-3494 | LOW 2.1 | citrix xenserver The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of | 0.4% | — |
| CVE-2012-1509 | HIGH 7.2 | vmware view Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors. | 0.4% | — |
| CVE-2011-1759 | MED 6.2 | linux linux_kernel Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory | 0.4% | — |
| CVE-2005-3356 | LOW 2.1 | linux linux_kernel The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice ("double decrement") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial o | 0.4% | — |
| CVE-2005-1762 | LOW 2.1 | linux linux_kernel The ptrace call in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform allows local users to cause a denial of service (kernel crash) via a "non-canonical" address. | 0.4% | — |
| CVE-2005-0756 | LOW 2.1 | linux linux_kernel ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash). | 0.4% | — |
| CVE-2005-0135 | LOW 2.1 | linux linux_kernel The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash). | 0.4% | — |
| CVE-2026-9938 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-86089 | HIGH 7.1 | apache nifi Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connec | 0.4% | — |
| CVE-2026-59285 | HIGH 8.1 | vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | 0.4% | — |
| CVE-2026-55955 | MED 6.5 | apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. | 0.4% | — |
| CVE-2026-41732 | HIGH 8.1 | vmware spring_for_apache_pulsar JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rat | 0.4% | — |
| CVE-2025-52948 | MED 5.9 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending specific, unknown traffic patterns to cause the FPC and system to crash and restart. | 0.4% | — |
| CVE-2024-38179 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-34117 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.4% | — |
| CVE-2024-3386 | MED 5.3 | paloaltonetworks pan-os An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to | 0.4% | — |
| CVE-2023-36568 | HIGH 7.0 | microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35337 | HIGH 7.8 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-26020 | MED 5.7 | craftercms crafter_cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1. | 0.4% | — |
| CVE-2023-23381 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2022-49997 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: lantiq_xrx200: restore buffer if memory allocation failed In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the syst | 0.4% | — |
| CVE-2022-35642 | MED 5.4 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus | 0.4% | — |
| CVE-2021-40683 | HIGH 7.8 | akamai enterprise_application_access In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution. | 0.4% | — |
| CVE-2021-20226 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing ope | 0.4% | — |