56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-24049 | HIGH 8.4 | microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-23159 | HIGH 8.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than ac | 0.2% | — |
| CVE-2025-22121 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff8880 | 0.2% | — |
| CVE-2025-22080 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check. The problem is that on 32bit systems if they're both gr | 0.2% | — |
| CVE-2025-21362 | HIGH 8.4 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-21354 | HIGH 8.4 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-56704 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device ID during IRQ release. [Dominique: remove confusing variable reset to 0] | 0.2% | — |
| CVE-2024-56684 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks() It should be size of the struct clk_bulk_data, not data pointer pass to devm_kcalloc(). | 0.2% | — |
| CVE-2024-56373 | HIGH 8.4 | apache airflow DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the con | 1.0% | — |
| CVE-2024-55639 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: renesas: rswitch: avoid use-after-put for a device tree node The device tree node saved in the rswitch_device structure is used at several driver locations. So passing this node to of_n | 0.2% | — |
| CVE-2024-53092 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct info pointer vp_modern_avq_cleanup() and vp_del_vqs() clean up admin vq resources by virtio_pci_vq_info pointer. The info pointer of admin v | 0.2% | — |
| CVE-2024-53082 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key_length check in virtnet_probe() to avoid possible out of bound errors when setting/reading the hash key. | 0.2% | — |
| CVE-2024-51459 | HIGH 8.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. | 0.1% | — |
| CVE-2024-50115 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits 4:0 of CR3 are ignored when PAE paging is used, and thus | 0.2% | — |
| CVE-2024-49105 | HIGH 8.4 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-49063 | HIGH 8.4 | microsoft muzic Microsoft/Muzic Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-46831 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: Fix use-after-free error in kunit test This is a clear use-after-free error. We remove it, and rely on checking the return code of vcap_del_rule. | 0.2% | — |
| CVE-2024-46823 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kunit/overflow: Fix UB in overflow_allocation_test The 'device_name' array doesn't exist out of the 'overflow_allocation_test' function scope. However, it is being used as a driver name when | 0.3% | — |
| CVE-2024-43497 | HIGH 8.4 | microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-39480 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buff | 0.3% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.6% | — |
| CVE-2024-38194 | HIGH 8.4 | microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | 1.3% | — |
| CVE-2024-37984 | HIGH 8.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-36973 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function g | 0.2% | — |
| CVE-2024-36910 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned | 0.2% | — |