58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-57882 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix TCP options overflow. Syzbot reported the following splat: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI | 0.5% | — |
| CVE-2023-47705 | MED 4.3 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228. | 0.5% | — |
| CVE-2023-20071 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Sno | 0.5% | — |
| CVE-2023-20053 | MED 6.1 | cisco nexus_dashboard A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vu | 0.5% | — |
| CVE-2022-44697 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41095 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-38427 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i | 0.5% | — |
| CVE-2022-38426 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i | 0.5% | — |
| CVE-2020-28097 | MED 5.9 | linux linux_kernel The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85. | 0.5% | — |
| CVE-2020-12771 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | 0.5% | — |
| CVE-2018-1978 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069. | 0.5% | — |
| CVE-2019-1645 | MED 4.3 | cisco connected_mobile_experiences A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for certai | 0.5% | — |
| CVE-2016-7081 | HIGH 7.8 | vmware workstation_player Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS via | 0.5% | — |
| CVE-2014-9900 | MED 5.5 | google android The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via | 0.5% | — |
| CVE-2012-2490 | MED 5.0 | cisco ip_communicator Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471. | 0.5% | — |
| CVE-2012-2390 | MED 4.9 | linux linux_kernel Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations. | 0.5% | — |
| CVE-2005-0532 | LOW 2.1 | linux linux_kernel The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between s | 0.5% | — |
| CVE-2026-78450 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-78449 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-72981 | HIGH 8.1 | microsoft windows_10_1607 Use after free in IP Helper allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-49845 | CRIT 9.8 | apache hive SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updat | 0.5% | — |
| CVE-2026-44822 | HIGH 8.2 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-20162 | HIGH 8.6 | cisco ios_xe A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to imp | 0.5% | — |
| CVE-2025-22042 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context. | 0.5% | — |
| CVE-2024-20426 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial | 0.5% | — |