IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-49507 HIGH 7.8 adobe indesign InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.5% —
CVE-2024-36013 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type void. Nothing is using th 0.5% —
CVE-2021-47132 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix sk_forward_memory corruption on retransmission MPTCP sk_forward_memory handling is a bit special, as such field is protected by the msk socket spin_lock, instead of the plain sock 0.5% —
CVE-2022-22305 MED 5.4 fortinet fortianalyzer An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthent 0.5% —
CVE-2023-40370 LOW 3.7 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470. 0.5% —
CVE-2023-20228 MED 6.1 cisco encs_5100_firmware A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due t 0.5% —
CVE-2023-29259 LOW 3.7 ibm sterling_connect\ IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055. 0.5% —
CVE-2021-42757 MED 6.7 fortinet fortiadc A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments. 0.5% —
CVE-2021-42993 HIGH 8.8 flexihub flexihub FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) 0.5% —
CVE-2019-19338 MED 5.5 linux linux_kernel A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affe 0.5% —
CVE-2015-3288 HIGH 7.8 linux linux_kernel mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero. 0.5% —
CVE-2006-7203 MED 4.0 linux linux_kernel The compat_sys_mount function in fs/compat.c in Linux kernel 2.6.20 and earlier allows local users to cause a denial of service (NULL pointer dereference and oops) by mounting a smbfs file system in compatibility mode ("mount -t smbfs"). 0.5% —
CVE-2026-59285 HIGH 8.1 vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 0.5% —
CVE-2026-67592 HIGH 7.5 apache qpid_protonj2 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are 0.5% —
CVE-2026-48331 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. 0.5% —
CVE-2026-66142 HIGH 7.5 apache neethi Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upg 0.5% —
CVE-2026-46155 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns succ 0.5% —
CVE-2026-43197 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netcons 0.5% —
CVE-2025-54947 CRIT 9.8 apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf 0.5% —
CVE-2025-58735 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-58732 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-34196 CRIT 9.8 vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in p 0.5% —
CVE-2023-53335 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is dereferenced later regardless of whether it is empty. This patc 0.5% —
CVE-2025-49680 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-32718 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. 0.5% —