58.181 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.181 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-4565 | LOW 2.1 | linux linux_kernel The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows | 0.5% | — |
| CVE-2026-81352 | HIGH 8.8 | microsoft web_media_extensions Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-69406 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68786 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-68775 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-67642 | HIGH 8.8 | microsoft sql_server_2025 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-67388 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-67385 | HIGH 8.8 | microsoft sql_server_2017 Use after free in SQL Server allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-67381 | HIGH 8.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-19298 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. | 0.5% | — |
| CVE-2026-64430 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardirq context ntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive the vector number. pci_irq_vector() calls msi_get_virq() t | 0.5% | — |
| CVE-2026-46024 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treat | 0.5% | — |
| CVE-2026-40564 | MED 6.5 | apache flink_kubernetes_operator Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a u | 0.5% | — |
| CVE-2026-43405 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Cur | 0.5% | — |
| CVE-2026-43099 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe() ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the IPv6 stack is not active (CONFIG_IPV6=m and not loaded), and passin | 0.5% | — |
| CVE-2026-26110 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-23240 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can | 0.5% | — |
| CVE-2026-20005 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0.5% | — |
| CVE-2025-49751 | MED 6.8 | microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0.5% | — |
| CVE-2025-53689 | HIGH 8.8 | apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja | 0.5% | — |
| CVE-2025-36048 | HIGH 7.2 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | 0.5% | — |
| CVE-2021-47041 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix incorrect locking in state_change sk callback We are not changing anything in the TCP connection state so we should not take a write_lock but rather a read lock. This caused | 0.5% | — |
| CVE-2023-38733 | MED 4.3 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. | 0.5% | — |
| CVE-2023-32553 | MED 5.3 | trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. | 0.5% | — |
| CVE-2022-38016 | HIGH 8.8 | microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.5% | — |