IT
56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.966 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-27675 MED 4.7 debian debian_linux An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer derefer 0.3%
CVE-2011-2060 MED 4.9 cisco 5500_series_adaptive_security_appliance The platform-sw component on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 before 8.2(5.3), 8.3 before 8.3(2.20), and 8.4 before 8.4(2.1) does not properly handle non-ASCII characters in an interface description, which allows l 0.3%
CVE-2026-68821 HIGH 7.3 microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50303 MED 5.5 microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-49174 MED 6.1 microsoft windows_10_1809 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-34346 MED 5.5 microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-20280 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple 0.3%
CVE-2026-20155 HIGH 8.0 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnera 0.3%
CVE-2026-20151 HIGH 7.3 cisco smart_software_manager_on-prem A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user in 0.3%
CVE-2026-11629 HIGH 8.8 google chrome Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-11017 MED 6.5 google chrome Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2025-49762 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-33142 MED 5.3 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections. 0.3%
CVE-2025-13720 HIGH 8.8 google chrome Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2025-13212 MED 5.3 ibm aspera_console IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency. 0.3%
CVE-2024-57996 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does not work correctly with a limit of 1. iproute2 actually checks for this and this patch adds the check in kernel 0.3%
CVE-2024-57980 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. Th 0.3%
CVE-2024-57901 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK Blamed commit forgot MSG_PEEK case, allowing a crash [1] as found by syzbot. Rework vlan_get_protocol_dgram() to not touch skb at all, s 0.3%
CVE-2024-56538 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any furt 0.3%
CVE-2024-53158 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to break if the frequency returned from clk_round_rate() is the same as on the previous iteration. How 0.3%
CVE-2024-50269 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: musb: sunxi: Fix accessing an released usb phy Commit 6ed05c68cbca ("usb: musb: sunxi: Explicitly release USB PHY on exit") will cause that usb phy @glue->xceiv is accessed after releas 0.3%
CVE-2024-50262 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds write in trie_get_next_key() trie_get_next_key() allocates a node stack with size trie->max_prefixlen, while it writes (trie->max_prefixlen + 1) nodes to the stack whe 0.3%
CVE-2024-41092 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix potential UAF by revoke of fence registers CI has been sporadically reporting the following issue triggered by igt@i915_selftest@live@hangcheck on ADL-P and similar machines 0.3%
CVE-2024-41059 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value in copy_name [syzbot reported] BUG: KMSAN: uninit-value in sized_strscpy+0xc4/0x160 sized_strscpy+0xc4/0x160 copy_name+0x2af/0x320 fs/hfsplus/xattr.c:411 hfsplus 0.3%
CVE-2024-40960 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible NULL dereference in rt6_probe() syzbot caught a NULL dereference in rt6_probe() [1] Bail out if __in6_dev_get() returns NULL. [1] Oops: general protection fault, pr 0.3%