IT
58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.462 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-32296 LOW 3.3 linux linux_kernel The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056. 0.4% —
CVE-2022-26808 HIGH 7.0 microsoft windows_10 Windows File Explorer Elevation of Privilege Vulnerability 0.4% —
CVE-2022-24959 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c. 0.4% —
CVE-2022-20953 MED 5.5 cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a 0.4% —
CVE-2021-43080 MED 4.6 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack t 0.4% —
CVE-2018-1799 MED 6.2 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429. 0.4% —
CVE-2016-10208 MED 4.3 linux linux_kernel The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 im 0.4% —
CVE-2014-3646 MED 5.5 canonical ubuntu_linux arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. 0.4% —
CVE-2014-3182 MED 6.9 linux linux_kernel Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provid 0.4% —
CVE-2010-3067 MED 4.9 canonical ubuntu_linux Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call. 0.4% —
CVE-2026-69477 HIGH 7.3 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-64067 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() an 0.4% —
CVE-2026-34614 MED 6.1 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within 0.4% —
CVE-2026-32149 HIGH 7.3 microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-27912 HIGH 8.0 microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. 0.4% —
CVE-2025-38124 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list sk 0.4% —
CVE-2025-27391 MED 6.5 apache artemis Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issu 0.4% —
CVE-2025-25255 MED 5.3 fortinet fortios An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 m 0.4% —
CVE-2025-21855 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer to VIOS, the tx_bytes stat was incremented by the length of the skb. It is invalid 0.4% —
CVE-2025-20193 MED 6.5 cisco ios_xe A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r This vulnerability is due to insufficient input validatio 0.4% —
CVE-2024-38158 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.4% —
CVE-2024-38136 HIGH 7.0 microsoft windows_10_1809 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability 0.4% —
CVE-2023-35829 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. 0.4% —
CVE-2023-0007 MED 6.5 paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrat 0.4% —
CVE-2022-50401 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure On error situation `clp->cl_cb_conn.cb_xprt` should not be given a reference to the xprt otherwise both client cleanup and 0.4% —