57.305 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.305 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-2406 | MED 6.9 | linux kernel Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors invol | 0.5% | — |
| CVE-2026-47288 | HIGH 7.1 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-40023 | MED 5.3 | apache log4cxx Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, ND | 0.5% | — |
| CVE-2026-31476 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRE | 0.5% | — |
| CVE-2026-22022 | HIGH 8.2 | apache solr Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that | 0.5% | — |
| CVE-2026-20146 | MED 5.5 | cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary fil | 0.5% | — |
| CVE-2026-20136 | MED 6.0 | cisco identity_services_engine A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying opera | 0.5% | — |
| CVE-2025-64899 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure | 0.5% | — |
| CVE-2025-54104 | MED 6.7 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53733 | HIGH 8.4 | microsoft 365_apps Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2024-43553 | HIGH 7.4 | microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-35970 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: af_unix: Clear stale u->oob_skb. syzkaller started to report deadlock of unix_gc_lock after commit 4090fa373f0e ("af_unix: Replace garbage collection algorithm."), but it just uncovers the b | 0.5% | — |
| CVE-2024-23607 | MED 5.5 | f5 f5os-a A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2024-22268 | HIGH 7.1 | vmware fusion VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial | 0.5% | — |
| CVE-2024-21586 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an a | 0.5% | — |
| CVE-2023-41742 | HIGH 7.5 | acronis agent Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | 0.5% | — |
| CVE-2022-20769 | HIGH 7.4 | cisco wireless_lan_controller_software A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insuff | 0.5% | — |
| CVE-2019-1972 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating sys | 0.5% | — |
| CVE-2019-11191 | LOW 2.5 | linux linux_kernel The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and t | 0.5% | — |
| CVE-2014-9892 | MED 5.5 | google android The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sens | 0.5% | — |
| CVE-2014-3183 | MED 6.9 | linux linux_kernel Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a craf | 0.5% | — |
| CVE-2012-0028 | HIGH 7.2 | linux linux_kernel The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child proce | 0.5% | — |
| CVE-2009-0322 | MED 4.9 | canonical ubuntu_linux drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in / | 0.5% | — |
| CVE-2005-3181 | LOW 2.1 | canonical ubuntu_linux The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak | 0.5% | — |
| CVE-2005-0001 | MED 6.9 | linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor | 0.5% | — |