IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-5180 HIGH 7.8 sparklabs viscosity Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection 0.4% —
CVE-2020-29372 MED 4.7 canonical ubuntu_linux An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e. 0.4% —
CVE-2019-1730 MED 6.7 cisco nx-os A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside o 0.4% —
CVE-2018-18913 HIGH 7.8 opera opera_browser Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full cont 0.4% —
CVE-2016-10907 HIGH 7.8 linux linux_kernel An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt. 0.4% —
CVE-2013-0290 MED 4.9 linux linux_kernel The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted applica 0.4% —
CVE-2012-6546 LOW 1.9 linux linux_kernel The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. 0.4% —
CVE-2010-4346 LOW 2.1 linux linux_kernel The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer derefer 0.4% —
CVE-2005-3660 MED 4.9 linux linux_kernel Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to fini 0.4% —
CVE-2004-0997 MED 4.6 linux linux_kernel Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors. 0.4% —
CVE-2026-69690 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4% —
CVE-2026-45602 CRIT 9.1 microsoft windows_10_1607 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. 0.4% —
CVE-2026-41729 HIGH 8.1 vmware spring_data_rest Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key 0.4% —
CVE-2026-3931 HIGH 8.8 google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2026-19306 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload 0.4% —
CVE-2025-62572 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62571 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62467 HIGH 7.8 microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62464 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62462 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62461 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-60720 HIGH 7.8 microsoft windows_10_1607 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-60713 HIGH 7.8 microsoft windows_server_2016 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59505 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55233 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —