57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1446 | LOW 1.9 | linux linux_kernel arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kernel memory, | 0.3% | — |
| CVE-2007-3850 | LOW 1.9 | linux linux_kernel The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space. | 0.3% | — |
| CVE-2006-5807 | MED 4.6 | cisco secure_desktop Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion". | 0.3% | — |
| CVE-2006-1066 | LOW 1.2 | linux linux_kernel Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during | 0.3% | — |
| CVE-1999-1276 | HIGH 7.2 | debian debian_linux fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. | 0.3% | — |
| CVE-2026-6317 | HIGH 8.8 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6316 | HIGH 8.8 | google chrome Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6300 | HIGH 8.8 | google chrome Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6299 | HIGH 8.8 | google chrome Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-47652 | HIGH 8.2 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-45604 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-4439 | HIGH 8.8 | google chrome Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-22745 | MED 5.3 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * | 0.3% | — |
| CVE-2026-20806 | MED 5.5 | microsoft windows_10_1809 Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2025-59213 | HIGH 8.8 | microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.3% | — |
| CVE-2025-27732 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-20129 | MED 4.3 | cisco socialminer A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper s | 0.3% | — |
| CVE-2024-8260 | MED 6.1 | openpolicyagent open_policy_agent A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI | 0.3% | — |
| CVE-2024-49513 | HIGH 7.8 | adobe pdf_library_sdk PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 0.3% | — |
| CVE-2024-37070 | MED 4.3 | ibm concert IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | 0.3% | — |
| CVE-2024-35937 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to | 0.3% | — |
| CVE-2024-35856 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double fr | 0.3% | — |
| CVE-2023-7016 | HIGH 7.8 | thalesgroup safenet_authentication_client A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | 0.3% | — |
| CVE-2023-38423 | MED 5.4 | f5 big-ip_access_policy_manager A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical | 0.3% | — |
| CVE-2023-36638 | MED 4.3 | fortinet fortianalyzer An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 al | 0.3% | — |