58.460 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.460 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8061 | HIGH 7.8 | linux linux_kernel drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have | 0.4% | — |
| CVE-2017-16649 | MED 6.6 | linux linux_kernel The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.4% | — |
| CVE-2016-6787 | HIGH 7.0 | linux linux_kernel kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 31095224. | 0.4% | — |
| CVE-2013-2635 | LOW 1.9 | linux linux_kernel The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. | 0.4% | — |
| CVE-2012-6548 | LOW 1.9 | linux linux_kernel The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application. | 0.4% | — |
| CVE-2012-3520 | LOW 1.9 | linux linux_kernel The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) | 0.4% | — |
| CVE-2011-4594 | MED 5.5 | linux linux_kernel The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference. | 0.4% | — |
| CVE-2011-1747 | MED 4.7 | linux linux_kernel The agp subsystem in the Linux kernel 2.6.38.5 and earlier does not properly restrict memory allocation by the (1) AGPIOC_RESERVE and (2) AGPIOC_ALLOCATE ioctls, which allows local users to cause a denial of service (memory consumption) by making many calls to | 0.4% | — |
| CVE-2008-2826 | MED 4.9 | canonical ubuntu_linux Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and | 0.4% | — |
| CVE-2006-5174 | LOW 2.1 | linux linux_kernel The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad ad | 0.4% | — |
| CVE-2026-61352 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-47889 | HIGH 7.5 | vmware spring_framework A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | 0.4% | — |
| CVE-2025-69624 | HIGH 7.5 | gonitro nitro_pdf_pro Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(ap | 0.4% | — |
| CVE-2025-65114 | HIGH 7.5 | apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the is | 0.4% | — |
| CVE-2025-58130 | CRIT 9.1 | apache fineract Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release. | 0.4% | — |
| CVE-2025-48820 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-34190 | HIGH 7.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (macOS/Linux client deployments) are vulnerable to an authentication bypass in PrinterInstallerClientService. The service require | 0.4% | — |
| CVE-2023-38246 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu | 0.4% | — |
| CVE-2023-35328 | HIGH 7.8 | microsoft windows_10_1507 Windows Transaction Manager Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35305 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35304 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-34442 | LOW 3.3 | apache camel Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0 | 0.4% | — |
| CVE-2023-33693 | MED 5.5 | tsingsee easyplayerpro A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file. | 0.4% | — |
| CVE-2023-2236 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a us | 0.4% | — |
| CVE-2023-21756 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability | 0.4% | — |