58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-5180 | HIGH 7.8 | sparklabs viscosity Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection | 0.4% | — |
| CVE-2020-29372 | MED 4.7 | canonical ubuntu_linux An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e. | 0.4% | — |
| CVE-2019-1730 | MED 6.7 | cisco nx-os A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside o | 0.4% | — |
| CVE-2018-18913 | HIGH 7.8 | opera opera_browser Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full cont | 0.4% | — |
| CVE-2016-10907 | HIGH 7.8 | linux linux_kernel An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt. | 0.4% | — |
| CVE-2013-0290 | MED 4.9 | linux linux_kernel The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted applica | 0.4% | — |
| CVE-2012-6546 | LOW 1.9 | linux linux_kernel The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. | 0.4% | — |
| CVE-2010-4346 | LOW 2.1 | linux linux_kernel The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer derefer | 0.4% | — |
| CVE-2005-3660 | MED 4.9 | linux linux_kernel Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to fini | 0.4% | — |
| CVE-2004-0997 | MED 4.6 | linux linux_kernel Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors. | 0.4% | — |
| CVE-2026-69690 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-45602 | CRIT 9.1 | microsoft windows_10_1607 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | 0.4% | — |
| CVE-2026-41729 | HIGH 8.1 | vmware spring_data_rest Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key | 0.4% | — |
| CVE-2026-3931 | HIGH 8.8 | google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2026-19306 | HIGH 7.7 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload | 0.4% | — |
| CVE-2025-62572 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62571 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62467 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62464 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62462 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62461 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60720 | HIGH 7.8 | microsoft windows_10_1607 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60713 | HIGH 7.8 | microsoft windows_server_2016 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59505 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55233 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |