IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-46904 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same the minor number causing a double unregistration of the same device. The first unregistratio 0.3%
CVE-2021-1219 HIGH 7.8 cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An 0.3%
CVE-2020-12898 HIGH 7.8 amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. 0.3%
CVE-2020-12893 HIGH 7.8 amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. 0.3%
CVE-2019-15962 MED 4.4 cisco telepresence_collaboration_endpoint A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attac 0.3%
CVE-2012-2373 MED 4.0 linux linux_kernel The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a 0.3%
CVE-2026-8547 HIGH 7.5 google chrome Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-66722 HIGH 7.2 apache cloudstack Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just th 0.3%
CVE-2026-65774 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65672 HIGH 7.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65671 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62799 HIGH 7.8 microsoft windows_11_26h1 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59276 MED 5.9 vmware spring_security Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject 0.3%
CVE-2026-50512 HIGH 7.8 microsoft pc_manager Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-39459 HIGH 7.2 f5 big-ip_access_policy_manager A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reac 0.3%
CVE-2026-32074 HIGH 7.8 microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32069 HIGH 7.8 microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-10890 HIGH 8.8 google chrome Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical) 0.3%
CVE-2025-52947 MED 6.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an interface, leading to 0.3%
CVE-2025-38524 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and 0.3%
CVE-2025-37925 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3 UID: 0 PI 0.3%
CVE-2025-33138 MED 5.4 ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. 0.3%
CVE-2025-24789 HIGH 7.8 snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is us 0.3%
CVE-2025-21753 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when attempting to join an aborted transaction When we are trying to join the current transaction and if it's aborted, we read its 'aborted' field after unlocking f 0.3%
CVE-2024-58007 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: soc: qcom: socinfo: Avoid out of bounds read of serial number On MSM8916 devices, the serial number exposed in sysfs is constant and does not change across individual devices. It's always: 0.3%