IT
57.361 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.361 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-64545 HIGH 7.5 In the Linux kernel, the following vulnerability has been resolved: net, bpf: check master for NULL in xdp_master_redirect() xdp_master_redirect() dereferences the result of netdev_master_upper_dev_get_rcu() without a NULL check, but that helper returns NULL 0.5%
CVE-2026-64374 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT RT migration is done aggressively. When a CPU schedules out a high priority RT task for a lower priority task, it will look to se 0.5%
CVE-2026-64312 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel fallback pcrypt installs pcrypt_aead_done() on the child AEAD request before trying to submit it through padata. If padata_do_parallel() r 0.5%
CVE-2026-64048 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt( 0.5%
CVE-2026-53003 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: pppoe: drop PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE sessions, an 0.5%
CVE-2026-52998 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the devic 0.5%
CVE-2026-52865 MED 6.5 f5 nginx_ingress_controller When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: Th 0.5%
CVE-2026-49328 MED 5.3 apache fesod Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image U 0.5%
CVE-2026-46177 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done. To avoid issues with BMCs that never say they 0.5%
CVE-2026-46102 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_strp() When the stream parser is aborted, for example after a message assembly timeout, it can still hold a reference to a partially assembled 0.5%
CVE-2026-46052 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: only d_add() negative dentries when they are unhashed Ceph can call d_add(dentry, NULL) on a negative dentry that is already present in the primary dcache hash. In the current VFS tha 0.5%
CVE-2026-46027 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wait_msg A CLC decline can be received while the handshake is still in an early stage, before the connection has been associated with a link group. 0.5%
CVE-2026-43373 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ncsi: fix skb leak in error paths Early return paths in NCSI RX and AEN handlers fail to release the received skb, resulting in a memory leak. Specifically, ncsi_aen_handler() returns 0.5%
CVE-2026-31563 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: macb: Use dev_consume_skb_any() to free TX SKBs The napi_consume_skb() function is not intended to be called in an IRQ disabled context. However, after commit 6bc8a5098bf4 ("net: macb: 0.5%
CVE-2026-31552 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom Since upstream commit e75665dd0968 ("wifi: wlcore: ensure skb headroom before skb_push"), wl1271_tx_allocate() 0.5%
CVE-2026-21227 HIGH 8.2 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-20852 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%
CVE-2026-20804 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%
CVE-2025-20150 MED 5.3 cisco nexus_dashboard A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sen 0.5%
CVE-2024-22254 HIGH 7.9 vmware cloud_foundation VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. 0.5%
CVE-2022-41095 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.5%
CVE-2022-31701 MED 5.3 vmware access VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. 0.5%
CVE-2020-5991 HIGH 7.8 nvidia cuda_toolkit NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure. 0.5%
CVE-2019-1700 MED 6.1 cisco firepower_9000_firmware A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to 0.5%
CVE-2018-18710 MED 5.5 canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. T 0.5%