IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-46331 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the h 0.6%
CVE-2026-44186 HIGH 7.3 apache http_server Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade t 0.6%
CVE-2024-47490 HIGH 8.2 juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network based attacker to cause increased consumption 0.6%
CVE-2024-37983 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-37976 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2023-5766 CRIT 9.8 devolutions remote_desktop_manager A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet. 0.6%
CVE-2019-19160 MED 5.7 cabsoftware reportexpress_proplus Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). 0.6%
CVE-2019-16232 MED 4.1 canonical ubuntu_linux drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. 0.6%
CVE-2018-7740 MED 5.5 canonical ubuntu_linux The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call. 0.6%
CVE-2018-15395 MED 5.4 cisco wireless_lan_controller_software A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this acce 0.6%
CVE-2015-7359 HIGH 7.8 ciphershed ciphershed The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impers 0.6%
CVE-2014-8133 LOW 2.1 linux linux_kernel arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, vi 0.6%
CVE-2012-2136 HIGH 7.2 linux linux_kernel The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privil 0.6%
CVE-2026-73016 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-71328 HIGH 8.8 microsoft .net Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-63039 CRIT 9.8 apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0 0.6%
CVE-2026-59242 MED 5.4 apache airflow Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-re 0.6%
CVE-2026-56160 CRIT 9.1 microsoft azure_red_hat_openshift Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-41608 HIGH 7.5 apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.6%
CVE-2026-32210 CRIT 9.3 microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-24015 CRIT 9.8 apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. 0.6%
CVE-2025-26675 HIGH 7.8 microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24044 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-20256 MED 6.5 cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands 0.6%
CVE-2024-30347 LOW 3.3 foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this 0.6%