58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.462 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-2812 | HIGH 7.8 | avaya communication_manager The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pa | 0.4% | — |
| CVE-2007-3104 | MED 4.9 | linux linux_kernel The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry. | 0.4% | — |
| CVE-2007-1496 | MED 4.9 | linux linux_kernel nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packet | 0.4% | — |
| CVE-2006-1524 | LOW 3.6 | linux linux_kernel madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this descrip | 0.4% | — |
| CVE-2005-4351 | MED 4.3 | dragonfly dragonfly The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system i | 0.4% | — |
| CVE-2026-70348 | MED 5.5 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-64406 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_acce | 0.4% | — |
| CVE-2026-53131 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb) | 0.4% | — |
| CVE-2026-10910 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-62557 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-11756 | HIGH 8.8 | google chrome Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2024-51736 | NONE 0.0 | sensiolabs symfony Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing comman | 0.4% | — |
| CVE-2024-49059 | HIGH 7.0 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-38137 | HIGH 7.0 | microsoft windows_10_21h2 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-26801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPIO reset mechanism would | 0.4% | — |
| CVE-2024-25698 | MED 6.1 | esri portal_for_arcgis There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute a | 0.4% | — |
| CVE-2023-53635 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that time | 0.4% | — |
| CVE-2023-32009 | HIGH 8.8 | microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-31167 | MED 5.0 | selinc sel-5036_acselerator_bay_screen_builder Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder Software on Windows allows Relative Path Traversal. SEL acSELerator Bay Screen Builde | 0.4% | — |
| CVE-2022-43845 | LOW 3.7 | ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. | 0.4% | — |
| CVE-2022-35285 | HIGH 8.8 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. | 0.4% | — |
| CVE-2022-20793 | MED 6.8 | cisco roomos A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerabili | 0.4% | — |
| CVE-2021-3146 | HIGH 7.8 | dolby audio_x2 The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges. | 0.4% | — |
| CVE-2020-3213 | MED 6.7 | cisco ios_xe A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system. The vulnerability is due to the ROMMON allowing for special parameters to be | 0.4% | — |
| CVE-2020-1677 | HIGH 7.2 | juniper mist_cloud_ui When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentica | 0.4% | — |