IT
58.181 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.181 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-4565 LOW 2.1 linux linux_kernel The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows 0.5%
CVE-2026-81352 HIGH 8.8 microsoft web_media_extensions Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-69406 MED 5.5 microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-68786 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-68775 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-67642 HIGH 8.8 microsoft sql_server_2025 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-67388 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-67385 HIGH 8.8 microsoft sql_server_2017 Use after free in SQL Server allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-67381 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-19298 HIGH 8.8 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. 0.5%
CVE-2026-64430 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardirq context ntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive the vector number. pci_irq_vector() calls msi_get_virq() t 0.5%
CVE-2026-46024 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treat 0.5%
CVE-2026-40564 MED 6.5 apache flink_kubernetes_operator Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a u 0.5%
CVE-2026-43405 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Cur 0.5%
CVE-2026-43099 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe() ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the IPv6 stack is not active (CONFIG_IPV6=m and not loaded), and passin 0.5%
CVE-2026-26110 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-23240 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can 0.5%
CVE-2026-20005 MED 5.8 cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil 0.5%
CVE-2025-49751 MED 6.8 microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. 0.5%
CVE-2025-53689 HIGH 8.8 apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja 0.5%
CVE-2025-36048 HIGH 7.2 ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. 0.5%
CVE-2021-47041 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix incorrect locking in state_change sk callback We are not changing anything in the TCP connection state so we should not take a write_lock but rather a read lock. This caused 0.5%
CVE-2023-38733 MED 4.3 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. 0.5%
CVE-2023-32553 MED 5.3 trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. 0.5%
CVE-2022-38016 HIGH 8.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5%