57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-3538 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-35086 | MED 6.5 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2025-66524 | HIGH 8.8 | apache nifi Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serial | 0.5% | — |
| CVE-2025-49667 | HIGH 7.8 | microsoft windows_10_1507 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-43576 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0.5% | — |
| CVE-2025-38089 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet. If | 0.5% | — |
| CVE-2025-29975 | HIGH 7.8 | microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-22042 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context. | 0.5% | — |
| CVE-2024-52052 | HIGH 7.2 | wowza streaming_engine Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. | 0.5% | — |
| CVE-2024-43530 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-22389 | HIGH 7.2 | f5 big-ip_access_policy_manager When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-21397 | MED 5.3 | microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-47131 | HIGH 7.5 | n-able passportal The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. | 0.5% | — |
| CVE-2023-32017 | HIGH 7.8 | microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2023-24862 | MED 5.5 | microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability | 0.5% | — |
| CVE-2023-22663 | MED 5.9 | intel unison_software Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0.5% | — |
| CVE-2023-21697 | MED 6.2 | microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-35758 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-0617 | MED 5.5 | debian debian_linux A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc | 0.5% | — |
| CVE-2021-1256 | MED 6.0 | cisco secure_firewall_threat_defense A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful exploit could cause syste | 0.5% | — |
| CVE-2020-9391 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwar | 0.5% | — |
| CVE-2019-15921 | MED 4.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.6. There is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c. | 0.5% | — |
| CVE-2018-6555 | HIGH 7.8 | canonical ubuntu_linux The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other i | 0.5% | — |
| CVE-2017-12134 | HIGH 8.8 | citrix xenserver The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leverag | 0.5% | — |
| CVE-2007-4786 | MED 5.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them | 0.5% | — |