58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-7872 | LOW 2.1 | linux linux_kernel The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands. | 0.5% | — |
| CVE-2004-1071 | HIGH 7.2 | linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code. | 0.5% | — |
| CVE-2004-1070 | HIGH 7.2 | linux linux_kernel The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory | 0.5% | — |
| CVE-2026-78444 | HIGH 8.1 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-26032 | MED 5.4 | apache ivy The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. Th | 0.5% | — |
| CVE-2026-58295 | HIGH 8.3 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-31432 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received, and the first command (READ) consumes most of the response b | 0.5% | — |
| CVE-2026-24293 | HIGH 7.8 | microsoft windows_10_21h2 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-62470 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2023-38113 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0.5% | — |
| CVE-2023-32012 | HIGH 7.8 | microsoft windows_10_21h2 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-3628 | MED 6.6 | linux linux_kernel A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges. | 0.5% | — |
| CVE-2022-1116 | HIGH 7.8 | linux linux_kernel Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions. | 0.5% | — |
| CVE-2021-22127 | HIGH 7.1 | fortinet forticlient An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into con | 0.5% | — |
| CVE-2020-3497 | HIGH 7.4 | cisco ios_xe Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of | 0.5% | — |
| CVE-2020-3493 | HIGH 7.4 | cisco ios_xe Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of | 0.5% | — |
| CVE-2020-3489 | HIGH 7.4 | cisco ios_xe Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of | 0.5% | — |
| CVE-2020-3488 | HIGH 7.4 | cisco ios_xe Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of | 0.5% | — |
| CVE-2019-12676 | HIGH 7.4 | cisco adaptive_security_appliance A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected devic | 0.5% | — |
| CVE-2019-1623 | MED 6.7 | cisco meeting_server A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CL | 0.5% | — |
| CVE-2018-5531 | HIGH 7.4 | f5 big-ip_access_policy_manager Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2). | 0.5% | — |
| CVE-2016-5243 | MED 5.5 | linux linux_kernel The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message. | 0.5% | — |
| CVE-2016-2550 | MED 5.5 | linux linux_kernel The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: | 0.5% | — |
| CVE-2015-7430 | HIGH 8.4 | apache hadoop The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors. | 0.5% | — |
| CVE-2014-1738 | LOW 2.1 | debian debian_linux The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel he | 0.5% | — |