58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.462 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-16531 | MED 6.6 | linux linux_kernel drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION de | 0.4% | — |
| CVE-2017-15951 | HIGH 7.8 | linux linux_kernel The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus finding a key in the "negative" state to avoid a race condition, which allows local users to cause a denial of service or possibly have unspecif | 0.4% | — |
| CVE-2016-3070 | HIGH 7.8 | debian debian_linux The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possib | 0.4% | — |
| CVE-2015-4265 | MED 4.9 | cisco ucs_b-series_blade_server_software Cisco Unified Computing System (UCS) B Blade Server Software 2.2.x before 2.2.6 allows local users to cause a denial of service (host OS or BMC hang) by sending crafted packets over the Inter-IC (I2C) bus, aka Bug ID CSCuq77241. | 0.4% | — |
| CVE-2012-1508 | HIGH 7.2 | vmware esx The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors. | 0.4% | — |
| CVE-2010-3296 | LOW 2.1 | canonical ubuntu_linux The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via | 0.4% | — |
| CVE-2010-2955 | LOW 2.1 | canonical ubuntu_linux The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_poin | 0.4% | — |
| CVE-2010-0003 | MED 5.4 | debian debian_linux The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then readin | 0.4% | — |
| CVE-2001-1551 | LOW 2.1 | linux linux_kernel Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs. | 0.4% | — |
| CVE-2026-8671 | HIGH 7.5 | avantra avantra Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. | 0.4% | — |
| CVE-2026-69376 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69367 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69345 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69308 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69303 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68895 | MED 5.5 | microsoft windows_10_1607 Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68881 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68843 | MED 5.5 | microsoft windows_10_1607 Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-32077 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-23112 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/off | 0.4% | — |
| CVE-2026-20068 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0.4% | — |
| CVE-2026-20053 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing V | 0.4% | — |
| CVE-2025-62216 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-62205 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |