56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.761 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-49947 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: binder: fix alloc->vma_vm_mm null-ptr dereference Syzbot reported a couple issues introduced by commit 44e602b4e52f ("binder_alloc: add missing mmap_lock calls when using the VMA"), in which | 0.2% | — |
| CVE-2022-49940 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() A null pointer dereference can happen when attempting to access the "gsm->receive()" function in gsmld_receive_buf(). Curre | 0.2% | — |
| CVE-2022-49775 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: cdg: allow tcp_cdg_release() to be called multiple times Apparently, mptcp is able to call tcp_disconnect() on an already disconnected flow. This is generally fine, unless current conge | 0.2% | — |
| CVE-2022-49599 | MED 4.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_l3mdev_accept. While reading sysctl_tcp_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers. | 0.2% | — |
| CVE-2022-48826 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix deadlock on DSI device attach error DSI device attach to DSI host will be done with host device's lock held. Un-registering host in "device attach" error path (ex: probe retry) | 0.2% | — |
| CVE-2022-4269 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the t | 0.2% | — |
| CVE-2021-47582 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: USB: core: Make do_proc_control() and do_proc_bulk() killable The USBDEVFS_CONTROL and USBDEVFS_BULK ioctls invoke usb_start_wait_urb(), which contains an uninterruptible wait with a user-sp | 0.2% | — |
| CVE-2021-47108 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check for CEA modes only") a check for CEA modes was added to function mtk_h | 0.2% | — |
| CVE-2021-31377 | MED 5.5 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated | 0.2% | — |
| CVE-2019-1586 | MED 4.6 | cisco application_policy_infrastructure_controller A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of c | 0.2% | — |
| CVE-2026-9942 | MED 5.0 | google chrome Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-7946 | MED 4.3 | google chrome Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: | 0.2% | — |
| CVE-2026-65783 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65782 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65781 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65780 | HIGH 7.0 | microsoft windows_11_24h2 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62892 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62774 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62773 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62749 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62725 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-53561 | HIGH 7.4 | apache hive An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network | 0.2% | — |
| CVE-2026-34341 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-2317 | MED 6.5 | google chrome Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-0270 | HIGH 7.5 | paloaltonetworks cortex_xsoar A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) | 0.2% | — |