IT
57.361 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.361 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2015-8374 MED 4.0 linux linux_kernel fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action. 0.5%
CVE-2026-53216 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buf 0.5%
CVE-2026-53215 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer 0.5%
CVE-2026-50370 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. 0.5%
CVE-2026-43406 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being less 0.5%
CVE-2026-43304 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buffer in process_auth_done() and generally has a sane length. T 0.5%
CVE-2026-31478 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add support for read compound"), response buffer management was chang 0.5%
CVE-2025-60709 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-50173 HIGH 7.8 microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-44184 MED 6.5 juniper junos An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a spec 0.5%
CVE-2023-35332 MED 6.8 microsoft windows_10_1507 Windows Remote Desktop Protocol Security Feature Bypass 0.5%
CVE-2022-31679 LOW 3.7 vmware spring_data_rest Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests t 0.5%
CVE-2022-30674 MED 5.5 adobe indesign Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit 0.5%
CVE-2021-34773 MED 6.5 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Un 0.5%
CVE-2021-20446 MED 5.4 ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr 0.5%
CVE-2021-1268 HIGH 7.4 cisco ios_xr A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists bec 0.5%
CVE-2020-8146 HIGH 7.8 ui unifi_video In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and ad 0.5%
CVE-2020-4933 MED 5.4 ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo 0.5%
CVE-2020-27820 MED 4.7 fedoraproject fedora A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver). 0.5%
CVE-2013-2146 MED 4.7 linux linux_kernel arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an incorrect bitmask, which allows local users to cause a denial of service (general protection fault and system crash) by atte 0.5%
CVE-2009-0269 MED 4.9 canonical ubuntu_linux fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to 0.5%
CVE-2026-65802 HIGH 7.4 microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-57097 MED 6.4 microsoft windows_10_1607 Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2026-45177 CRIT 9.1 paloaltonetworks idira_secrets_manager_edge Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, 0.5%
CVE-2026-42827 MED 6.5 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.5%