IT
58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.462 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-16531 MED 6.6 linux linux_kernel drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION de 0.4% —
CVE-2017-15951 HIGH 7.8 linux linux_kernel The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus finding a key in the "negative" state to avoid a race condition, which allows local users to cause a denial of service or possibly have unspecif 0.4% —
CVE-2016-3070 HIGH 7.8 debian debian_linux The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possib 0.4% —
CVE-2015-4265 MED 4.9 cisco ucs_b-series_blade_server_software Cisco Unified Computing System (UCS) B Blade Server Software 2.2.x before 2.2.6 allows local users to cause a denial of service (host OS or BMC hang) by sending crafted packets over the Inter-IC (I2C) bus, aka Bug ID CSCuq77241. 0.4% —
CVE-2012-1508 HIGH 7.2 vmware esx The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors. 0.4% —
CVE-2010-3296 LOW 2.1 canonical ubuntu_linux The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via 0.4% —
CVE-2010-2955 LOW 2.1 canonical ubuntu_linux The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_poin 0.4% —
CVE-2010-0003 MED 5.4 debian debian_linux The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then readin 0.4% —
CVE-2001-1551 LOW 2.1 linux linux_kernel Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs. 0.4% —
CVE-2026-8671 HIGH 7.5 avantra avantra Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. 0.4% —
CVE-2026-69376 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69367 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69345 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69308 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69303 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-68895 MED 5.5 microsoft windows_10_1607 Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-68881 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-68843 MED 5.5 microsoft windows_10_1607 Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-3542 HIGH 8.8 google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-32077 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-23112 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/off 0.4% —
CVE-2026-20068 MED 5.8 cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil 0.4% —
CVE-2026-20053 MED 5.8 cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing V 0.4% —
CVE-2025-62216 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-62205 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4% —