58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-2210 | LOW 2.1 | linux linux_kernel The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kernel mem | 0.5% | — |
| CVE-2012-2273 | MED 4.9 | comodo comodo_internet_security Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel ImageBase value. | 0.5% | — |
| CVE-2026-87512 | CRIT 9.6 | google chrome Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-48834 | HIGH 7.5 | apache answer Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessiv | 0.5% | — |
| CVE-2026-67590 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue | 0.5% | — |
| CVE-2026-67589 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes | 0.5% | — |
| CVE-2026-17707 | MED 6.5 | google chrome Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severit | 0.5% | — |
| CVE-2026-56163 | CRIT 10.0 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-49268 | CRIT 9.1 | apache shiro A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. T | 0.5% | — |
| CVE-2026-47280 | CRIT 10.0 | microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-42822 | CRIT 10.0 | microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-20811 | HIGH 7.8 | microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-20386 | HIGH 8.0 | splunk splunk In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets n | 0.5% | — |
| CVE-2025-48459 | MED 5.3 | apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | 0.5% | — |
| CVE-2024-43115 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which | 0.5% | — |
| CVE-2025-23335 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to d | 0.5% | — |
| CVE-2025-47174 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2023-2971 | MED 6.3 | typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo | 0.5% | — |
| CVE-2023-35342 | HIGH 7.8 | microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35312 | HIGH 7.8 | microsoft windows_10_1507 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-20167 | MED 6.0 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabi | 0.5% | — |
| CVE-2022-35850 | MED 4.3 | fortinet fortiauthenticator An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected | 0.5% | — |
| CVE-2023-21755 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44680 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44677 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.5% | — |