58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-3756 | HIGH 7.8 | lenovo thinkpad_10_ella_2 A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | 0.4% | — |
| CVE-2017-18202 | HIGH 7.0 | linux linux_kernel The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a co | 0.4% | — |
| CVE-2017-17053 | HIGH 7.0 | linux linux_kernel The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have | 0.4% | — |
| CVE-2014-9090 | MED 4.9 | linux linux_kernel The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a modify_ldt s | 0.4% | — |
| CVE-2014-7207 | MED 4.9 | linux linux_kernel A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system cras | 0.4% | — |
| CVE-2012-0058 | MED 5.5 | linux linux_kernel The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management. | 0.4% | — |
| CVE-2011-1171 | LOW 2.1 | linux linux_kernel net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitiv | 0.4% | — |
| CVE-2011-1170 | LOW 2.1 | linux linux_kernel net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensiti | 0.4% | — |
| CVE-2010-3015 | MED 4.7 | linux linux_kernel Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a sync opera | 0.4% | — |
| CVE-2006-2445 | MED 4.0 | linux linux_kernel Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting. | 0.4% | — |
| CVE-2006-0554 | LOW 1.7 | linux linux_kernel Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data. | 0.4% | — |
| CVE-2005-1369 | LOW 2.1 | linux linux_kernel The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs "alarms" file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to | 0.4% | — |
| CVE-2026-73632 | MED 4.3 | apache struts Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Onl | 0.4% | — |
| CVE-2026-73631 | MED 4.3 | apache struts Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing | 0.4% | — |
| CVE-2026-50475 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-43176 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate release report content before using for RTL8922DE The commit 957eda596c76 ("wifi: rtw89: pci: validate sequence number of TX release report") does validation on ex | 0.4% | — |
| CVE-2026-43172 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is an overrun of the array. Reje | 0.4% | — |
| CVE-2026-19300 | HIGH 7.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. | 0.4% | — |
| CVE-2025-59511 | HIGH 7.8 | microsoft windows_10_1809 External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-29838 | HIGH 7.4 | microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-0525 | HIGH 7.5 | octopus octopus_server In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server. | 0.4% | — |
| CVE-2024-54171 | HIGH 7.1 | ibm entirex IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | 0.4% | — |
| CVE-2024-35999 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb3: missing lock when picking channel Coverity spotted a place where we should have been holding the channel lock when accessing the ses channel index. Addresses-Coverity: 1582039 ("Data | 0.4% | — |
| CVE-2024-35969 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it still means hlist_for_each_entry_rcu can return an ite | 0.4% | — |
| CVE-2024-21597 | MED 5.3 | juniper junos An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) s | 0.4% | — |