IT
56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.761 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-49947 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: binder: fix alloc->vma_vm_mm null-ptr dereference Syzbot reported a couple issues introduced by commit 44e602b4e52f ("binder_alloc: add missing mmap_lock calls when using the VMA"), in which 0.2%
CVE-2022-49940 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() A null pointer dereference can happen when attempting to access the "gsm->receive()" function in gsmld_receive_buf(). Curre 0.2%
CVE-2022-49775 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: cdg: allow tcp_cdg_release() to be called multiple times Apparently, mptcp is able to call tcp_disconnect() on an already disconnected flow. This is generally fine, unless current conge 0.2%
CVE-2022-49599 MED 4.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_l3mdev_accept. While reading sysctl_tcp_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers. 0.2%
CVE-2022-48826 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix deadlock on DSI device attach error DSI device attach to DSI host will be done with host device's lock held. Un-registering host in "device attach" error path (ex: probe retry) 0.2%
CVE-2022-4269 MED 5.5 linux linux_kernel A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the t 0.2%
CVE-2021-47582 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: USB: core: Make do_proc_control() and do_proc_bulk() killable The USBDEVFS_CONTROL and USBDEVFS_BULK ioctls invoke usb_start_wait_urb(), which contains an uninterruptible wait with a user-sp 0.2%
CVE-2021-47108 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check for CEA modes only") a check for CEA modes was added to function mtk_h 0.2%
CVE-2021-31377 MED 5.5 juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated 0.2%
CVE-2019-1586 MED 4.6 cisco application_policy_infrastructure_controller A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of c 0.2%
CVE-2026-9942 MED 5.0 google chrome Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-7946 MED 4.3 google chrome Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: 0.2%
CVE-2026-65783 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65782 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65781 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65780 HIGH 7.0 microsoft windows_11_24h2 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62892 HIGH 7.0 microsoft windows_10_1809 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62774 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62773 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62749 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62725 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-53561 HIGH 7.4 apache hive An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network 0.2%
CVE-2026-34341 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-2317 MED 6.5 google chrome Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0.2%
CVE-2026-0270 HIGH 7.5 paloaltonetworks cortex_xsoar A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) 0.2%