IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-2962 HIGH 7.2 canonical ubuntu_linux drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users 0.5% —
CVE-2026-64607 MED 5.3 apache httpclient HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not a 0.5% —
CVE-2026-57101 HIGH 7.1 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.5% —
CVE-2026-55139 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2026-43074 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concur 0.5% —
CVE-2026-20941 HIGH 7.8 microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2026-20936 MED 4.3 microsoft windows_10_1607 Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-21860 MED 5.3 palletsprojects werkzeug Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, 0.5% —
CVE-2025-20350 HIGH 7.5 cisco desk_phone_9841_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vu 0.5% —
CVE-2025-54915 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-21927 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a p 0.5% —
CVE-2024-38337 CRIT 9.1 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments. 0.5% —
CVE-2021-28656 MED 5.4 apache zeppelin Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. 0.5% —
CVE-2024-21304 MED 4.1 microsoft windows_10_1809 Trusted Compute Base Elevation of Privilege Vulnerability 0.5% —
CVE-2022-20776 MED 5.5 cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a 0.5% —
CVE-2022-39843 HIGH 7.8 lotus_1-2-3_project lotus_1-2-3 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing r 0.5% —
CVE-2021-29738 MED 5.4 ibm infosphere_information_server IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration 0.5% —
CVE-2021-41363 MED 4.2 microsoft intune_management_extension Intune Management Extension Security Feature Bypass Vulnerability 0.5% —
CVE-2020-24563 HIGH 7.8 trendmicro apex_one A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain t 0.5% —
CVE-2019-1416 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. 0.5% —
CVE-2017-16643 MED 6.6 linux linux_kernel The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device. 0.5% —
CVE-2017-2344 HIGH 7.8 juniper junos A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow. Malicious exploitation of this issue may lead to a denial of service (kernel panic) or be leveraged as a privilege escalation through local code execution. The routines a 0.5% —
CVE-2012-2498 MED 4.0 cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197. 0.5% —
CVE-2011-2211 HIGH 7.2 linux linux_kernel The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allows local users to gain privileges by writing a certain integer value to kernel memory. 0.5% —
CVE-2005-1768 LOW 3.7 linux linux_kernel Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that incr 0.5% —