56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-48423 | HIGH 7.8 | linux linux_kernel In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur. | 0.3% | — |
| CVE-2022-42258 | MED 5.3 | debian debian_linux NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure. | 0.3% | — |
| CVE-2022-42257 | MED 5.3 | debian debian_linux NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service. | 0.3% | — |
| CVE-2022-28198 | MED 6.6 | nvidia omniverse_cache NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability. | 0.3% | — |
| CVE-2021-34724 | MED 6.0 | cisco ios_xe_sd-wan A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device a | 0.3% | — |
| CVE-2021-34711 | MED 5.5 | cisco ip_conference_phone_7832_firmware A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by p | 0.3% | — |
| CVE-2021-20536 | MED 6.2 | ibm spectrum_protect_plus IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836. | 0.3% | — |
| CVE-2021-1054 | MED 5.5 | nvidia gpu_driver NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to acce | 0.3% | — |
| CVE-2018-12633 | MED 6.3 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread | 0.3% | — |
| CVE-2014-4813 | MED 6.9 | ibm tivoli_storage_manager Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to | 0.3% | — |
| CVE-2026-9258 | MED 6.5 | canon eos_network_setting_tool Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0.3% | — |
| CVE-2026-8530 | HIGH 8.3 | google chrome Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7984 | HIGH 8.8 | google chrome Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-7974 | HIGH 8.8 | google chrome Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-7938 | HIGH 8.8 | google chrome Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-7926 | HIGH 8.8 | google chrome Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7921 | HIGH 8.8 | google chrome Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7907 | HIGH 8.8 | google chrome Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7906 | HIGH 8.8 | google chrome Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-65810 | HIGH 7.8 | microsoft .net_framework Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-64095 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid double decrement of bla.num_requests The bla.num_requests is increased when no request_sent was in progress. And it is decremented in various places (announcement was | 0.3% | — |
| CVE-2026-50634 | MED 6.5 | apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h | 0.3% | — |
| CVE-2026-48583 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48302 | MED 6.2 | adobe c2pa CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitati | 0.3% | — |
| CVE-2026-47849 | HIGH 7.1 | vmware spring_data_rest Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Dat | 0.3% | — |