58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-2208 | LOW 2.1 | linux linux_kernel Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call. | 0.5% | — |
| CVE-2008-3686 | MED 4.9 | linux linux_kernel The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which triggers a NULL | 0.5% | — |
| CVE-2005-0530 | LOW 2.1 | linux linux_kernel Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument. | 0.5% | — |
| CVE-2026-72971 | MED 5.5 | microsoft windows_11_26h1 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-55898 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-42913 | HIGH 7.5 | microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-29226 | HIGH 7.3 | apache ofbiz Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2026-35561 | HIGH 7.4 | amazon athena_odbc Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-ba | 0.5% | — |
| CVE-2025-64669 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-62455 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-47569 | MED 4.3 | fortinet fortimail A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 | 0.5% | — |
| CVE-2025-34235 | HIGH 7.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS certi | 0.5% | — |
| CVE-2024-54169 | MED 6.5 | ibm entirex IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | 0.5% | — |
| CVE-2024-39542 | HIGH 7.5 | juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 or LC9600, MX304, and Junos OS Evolved on ACX Series and PTX Series allows an unauthenticated, | 0.5% | — |
| CVE-2023-20120 | MED 5.4 | cisco secure_email_and_web_manager Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Secur | 0.5% | — |
| CVE-2023-20028 | MED 5.4 | cisco secure_email_and_web_manager Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Secur | 0.5% | — |
| CVE-2022-43573 | LOW 3.1 | ibm robotic_process_automation IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678. | 0.5% | — |
| CVE-2022-44502 | MED 5.5 | adobe illustrator Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exp | 0.5% | — |
| CVE-2022-44689 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41031 | HIGH 7.8 | fortinet forticlient A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESN | 0.5% | — |
| CVE-2021-42739 | MED 6.7 | debian debian_linux The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking. | 0.5% | — |
| CVE-2021-20100 | MED 6.7 | tenable nessus Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021 | 0.5% | — |
| CVE-2019-19067 | MED 4.4 | canonical ubuntu_linux Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failu | 0.5% | — |
| CVE-2018-7566 | HIGH 7.8 | canonical ubuntu_linux The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. | 0.5% | — |