56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-46904 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same the minor number causing a double unregistration of the same device. The first unregistratio | 0.3% | — |
| CVE-2021-1219 | HIGH 7.8 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An | 0.3% | — |
| CVE-2020-12898 | HIGH 7.8 | amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | 0.3% | — |
| CVE-2020-12893 | HIGH 7.8 | amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. | 0.3% | — |
| CVE-2019-15962 | MED 4.4 | cisco telepresence_collaboration_endpoint A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attac | 0.3% | — |
| CVE-2012-2373 | MED 4.0 | linux linux_kernel The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a | 0.3% | — |
| CVE-2026-8547 | HIGH 7.5 | google chrome Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-66722 | HIGH 7.2 | apache cloudstack Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just th | 0.3% | — |
| CVE-2026-65774 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65672 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65671 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62799 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-59276 | MED 5.9 | vmware spring_security Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject | 0.3% | — |
| CVE-2026-50512 | HIGH 7.8 | microsoft pc_manager Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-39459 | HIGH 7.2 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reac | 0.3% | — |
| CVE-2026-32074 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32069 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-10890 | HIGH 8.8 | google chrome Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2025-52947 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an interface, leading to | 0.3% | — |
| CVE-2025-38524 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and | 0.3% | — |
| CVE-2025-37925 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3 UID: 0 PI | 0.3% | — |
| CVE-2025-33138 | MED 5.4 | ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | 0.3% | — |
| CVE-2025-24789 | HIGH 7.8 | snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is us | 0.3% | — |
| CVE-2025-21753 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when attempting to join an aborted transaction When we are trying to join the current transaction and if it's aborted, we read its 'aborted' field after unlocking f | 0.3% | — |
| CVE-2024-58007 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: soc: qcom: socinfo: Avoid out of bounds read of serial number On MSM8916 devices, the serial number exposed in sysfs is constant and does not change across individual devices. It's always: | 0.3% | — |