58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-15127 | MED 5.5 | linux linux_kernel A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG). | 0.4% | — |
| CVE-2017-1439 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058. | 0.4% | — |
| CVE-2017-1438 | MED 6.7 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057. | 0.4% | — |
| CVE-2016-0226 | HIGH 7.8 | ibm informix_dynamic_server The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file. | 0.4% | — |
| CVE-2012-3511 | MED 6.2 | linux linux_kernel Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call. | 0.4% | — |
| CVE-2010-5164 | MED 5.3 | kingsoft personal_firewall_9 Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection | 0.4% | — |
| CVE-2006-0035 | MED 4.9 | linux linux_kernel The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0. | 0.4% | — |
| CVE-2005-0508 | MED 4.6 | Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue." | 0.4% | — |
| CVE-2026-84842 | HIGH 8.1 | ibm guardium_data_protection IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact | 0.4% | — |
| CVE-2026-76420 | CRIT 9.0 | A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization | 0.4% | — |
| CVE-2026-21255 | HIGH 8.8 | microsoft windows_10_1607 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-21219 | HIGH 7.0 | microsoft windows_software_development_kit Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-59206 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-52982 | MED 5.9 | juniper junos An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an MX Series device with an MS-MPC is config | 0.4% | — |
| CVE-2025-49675 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-49661 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-49660 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-48816 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-48806 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-48805 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-47996 | HIGH 7.8 | microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47993 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-38211 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the last deref") simplified cm_id resource management by freein | 0.4% | — |
| CVE-2024-54138 | MED 6.1 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately | 0.4% | — |
| CVE-2024-43511 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |