IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2006-6696 MED 6.9 microsoft windows_2000 Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime 3.4% —
CVE-2006-0038 MED 6.9 linux linux_kernel Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function. 0.4% —
CVE-2005-0767 MED 6.9 linux linux_kernel Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root. 0.4% —
CVE-2005-0001 MED 6.9 linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor 0.5% —
CVE-2026-9261 MED 6.8 canon eos_network_setting_tool Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier 0.3% —
CVE-2026-78451 MED 6.8 microsoft windows_10_1809 Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-77892 MED 6.8 microsoft windows_10_1607 No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-73180 MED 6.8 apache tomcat Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not b 0.4% —
CVE-2026-72999 MED 6.8 microsoft windows_10_1607 Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-72985 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-71350 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-71349 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-71348 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-71329 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. 0.3% —
CVE-2026-69566 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-69490 MED 6.8 microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-69415 MED 6.8 microsoft windows_10_1607 Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-68833 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. 0.3% —
CVE-2026-66313 MED 6.8 microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. 0.2% —
CVE-2026-65812 MED 6.8 microsoft teams Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. 0.9% —
CVE-2026-65086 MED 6.8 nvidia openshell NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. 2.4% —
CVE-2026-62702 MED 6.8 microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. 0.9% —
CVE-2026-62699 MED 6.8 microsoft windows_10_1607 Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-59311 MED 6.8 vmware spring_integration A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0. 0.4% —
CVE-2026-59272 MED 6.8 vmware spring_advanced_message_queuing_protocol Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2 0.3% —