57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-52946 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in send_sigio() and send_sigurg() when a process group receives a s | 0.6% | — |
| CVE-2025-47168 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-29837 | MED 5.5 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-53167 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs/blocklayout: Don't attempt unregister for invalid block device Since commit d869da91cccb ("nfs/blocklayout: Fix premature PR key unregistration") an unmount of a pNFS SCSI layout-enabled | 0.6% | — |
| CVE-2023-52290 | HIGH 8.1 | apache streampark In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is | 0.6% | — |
| CVE-2024-27018 | HIGH 8.2 | fedoraproject fedora In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook for promisc packets For historical reasons, when bridge device is in promisc mode, packets that are directed to the taps follow bridge inpu | 0.6% | — |
| CVE-2023-52610 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation. If frags arrive in order, the last frag's reference is reset in: inet_frag_reasm_prep | 0.6% | — |
| CVE-2021-47130 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool is empty, the nvme target is still trying to free the sgl from the p2p pool instead of the regular sgl poo | 0.6% | — |
| CVE-2024-26626 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel NULL pointer dereference, address: 0000000000000092 [ 86.306815] #PF: supervisor read ac | 0.6% | — |
| CVE-2024-21315 | HIGH 7.8 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-27516 | MED 5.3 | citrix application_delivery_controller_firmware User login brute force protection functionality bypass | 0.6% | — |
| CVE-2021-1270 | MED 6.3 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabili | 0.6% | — |
| CVE-2021-0222 | HIGH 7.4 | juniper junos A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets, which should be dis | 0.6% | — |
| CVE-2020-3390 | HIGH 7.4 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexp | 0.6% | — |
| CVE-2020-2013 | HIGH 8.3 | paloaltonetworks pan-os A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall wi | 0.6% | — |
| CVE-2018-12896 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger tha | 0.6% | — |
| CVE-2017-1000363 | HIGH 7.8 | debian debian_linux Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a | 0.6% | — |
| CVE-2017-0465 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proces | 0.6% | — |
| CVE-2016-6259 | MED 6.2 | citrix xenserver Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety c | 0.6% | — |
| CVE-2026-34327 | HIGH 8.2 | microsoft partner_center Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-59328 | MED 6.5 | apache fory A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payload that, when processed, consumes an ex | 0.6% | — |
| CVE-2024-47502 | HIGH 7.5 | juniper junos_os_evolved An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In specific cases the state of TCP sessions that are | 0.6% | — |
| CVE-2021-38963 | HIGH 8.0 | ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnera | 0.6% | — |
| CVE-2021-47368 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from | 0.6% | — |
| CVE-2024-26175 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |