58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49507 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.5% | — |
| CVE-2024-36013 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type void. Nothing is using th | 0.5% | — |
| CVE-2021-47132 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix sk_forward_memory corruption on retransmission MPTCP sk_forward_memory handling is a bit special, as such field is protected by the msk socket spin_lock, instead of the plain sock | 0.5% | — |
| CVE-2022-22305 | MED 5.4 | fortinet fortianalyzer An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthent | 0.5% | — |
| CVE-2023-40370 | LOW 3.7 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470. | 0.5% | — |
| CVE-2023-20228 | MED 6.1 | cisco encs_5100_firmware A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due t | 0.5% | — |
| CVE-2023-29259 | LOW 3.7 | ibm sterling_connect\ IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055. | 0.5% | — |
| CVE-2021-42757 | MED 6.7 | fortinet fortiadc A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments. | 0.5% | — |
| CVE-2021-42993 | HIGH 8.8 | flexihub flexihub FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) | 0.5% | — |
| CVE-2019-19338 | MED 5.5 | linux linux_kernel A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affe | 0.5% | — |
| CVE-2015-3288 | HIGH 7.8 | linux linux_kernel mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero. | 0.5% | — |
| CVE-2006-7203 | MED 4.0 | linux linux_kernel The compat_sys_mount function in fs/compat.c in Linux kernel 2.6.20 and earlier allows local users to cause a denial of service (NULL pointer dereference and oops) by mounting a smbfs file system in compatibility mode ("mount -t smbfs"). | 0.5% | — |
| CVE-2026-59285 | HIGH 8.1 | vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | 0.5% | — |
| CVE-2026-67592 | HIGH 7.5 | apache qpid_protonj2 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are | 0.5% | — |
| CVE-2026-48331 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | 0.5% | — |
| CVE-2026-66142 | HIGH 7.5 | apache neethi Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upg | 0.5% | — |
| CVE-2026-46155 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns succ | 0.5% | — |
| CVE-2026-43197 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netcons | 0.5% | — |
| CVE-2025-54947 | CRIT 9.8 | apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf | 0.5% | — |
| CVE-2025-58735 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-58732 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-34196 | CRIT 9.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in p | 0.5% | — |
| CVE-2023-53335 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is dereferenced later regardless of whether it is empty. This patc | 0.5% | — |
| CVE-2025-49680 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-32718 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. | 0.5% | — |