57.080 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.080 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43184 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rnbd-srv: Zero the rsp buffer before using it Before using the data buffer to send back the response message, zero it completely. This prevents any stray bytes to be picked up by the client | 0.4% | — |
| CVE-2026-41873 | CRIT 9.8 | apache pony_mail ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a P | 0.4% | — |
| CVE-2026-31589 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call filemap_free_folio() if we have a reference to (or hold a lock on) the mapping. Otherwise, we've already remove | 0.4% | — |
| CVE-2025-62232 | HIGH 7.5 | apache apisix Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed | 0.4% | — |
| CVE-2025-53734 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2024-30302 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of t | 0.4% | — |
| CVE-2024-26926 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object() Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") introduced changes to how binder objects are copied. In do | 0.4% | — |
| CVE-2023-49106 | MED 4.6 | hitachi device_manager Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04. | 0.4% | — |
| CVE-2023-26273 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134. | 0.4% | — |
| CVE-2023-24946 | HIGH 7.8 | microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-22384 | MED 4.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. | 0.4% | — |
| CVE-2020-36694 | MED 6.7 | linux linux_kernel An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with th | 0.4% | — |
| CVE-2019-5667 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiSetRootPageTable in which the application dereferences a pointer that it expects to be valid, but is NULL, which may lead to code execution, d | 0.4% | — |
| CVE-2019-1839 | MED 6.7 | cisco cbr-8_firmware A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly san | 0.4% | — |
| CVE-2019-12381 | MED 5.5 | linux linux_kernel An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is | 0.4% | — |
| CVE-2015-4244 | HIGH 7.2 | cisco asr_5000_series_software The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278. | 0.4% | — |
| CVE-2011-4330 | HIGH 7.2 | linux linux_kernel Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field. | 0.4% | — |
| CVE-2009-3939 | HIGH 7.1 | avaya aura_application_enablement_services The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | 0.4% | — |
| CVE-2008-3389 | MED 4.6 | ingres ingres Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before ru | 0.4% | — |
| CVE-2007-6267 | LOW 2.1 | citrix edgesight_for_endpoints Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information. | 0.4% | — |
| CVE-2004-0565 | LOW 2.1 | gentoo linux Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit. | 0.4% | — |
| CVE-2004-0003 | MED 4.6 | linux linux_kernel Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking." | 0.4% | — |
| CVE-2026-66756 | CRIT 9.8 | apache tika Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. | 0.4% | — |
| CVE-2026-59243 | CRIT 9.8 | apache apache-airflow-providers-fab The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary us | 0.4% | — |
| CVE-2026-52983 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix BQL imbalance in TX path Fix a possible BQL imbalance in airoha_dev_xmit(), where inflight packets are accounted only for the AIROHA_NUM_TX_RING netdev TX queues. The queue | 0.4% | — |