58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69315 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68886 | MED 5.5 | microsoft windows_10_1607 Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-58301 | MED 6.5 | apache shiro When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Ap | 0.5% | — |
| CVE-2026-64394 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE") added a fp->da | 0.5% | — |
| CVE-2026-53390 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl() validates the ACE header size and caps sid.num_subauth at SID_MAX_SUB_AUTHORITIE | 0.5% | — |
| CVE-2026-13473 | HIGH 8.1 | ibm storage_protect IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary co | 0.5% | — |
| CVE-2025-39841 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred receive path Fix a use-after-free window by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buf | 0.5% | — |
| CVE-2025-49682 | HIGH 7.3 | microsoft windows_10_21h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-22059 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: udp: Fix multiple wraparounds of sk->sk_rmem_alloc. __udp_enqueue_schedule_skb() has the following condition: if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf) goto drop; sk | 0.5% | — |
| CVE-2023-36633 | MED 5.4 | fortinet fortimail An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests. | 0.5% | — |
| CVE-2023-20068 | MED 6.1 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vu | 0.5% | — |
| CVE-2022-28881 | MED 4.3 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine crash. The exploit can be triggered remotely by an attacker. | 0.5% | — |
| CVE-2021-34803 | HIGH 7.8 | teamviewer teamviewer TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. | 0.5% | — |
| CVE-2020-3958 | MED 5.5 | vmware esxi VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of | 0.5% | — |
| CVE-2018-10853 | HIGH 7.0 | canonical ubuntu_linux A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use th | 0.5% | — |
| CVE-2017-7482 | HIGH 7.8 | debian debian_linux In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could pos | 0.5% | — |
| CVE-2017-17741 | MED 6.5 | debian debian_linux The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h. | 0.5% | — |
| CVE-2017-15115 | HIGH 7.8 | canonical ubuntu_linux The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have u | 0.5% | — |
| CVE-2012-4135 | MED 4.6 | cisco nx-os Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275. | 0.5% | — |
| CVE-2004-0535 | LOW 2.1 | conectiva linux The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources. | 0.5% | — |
| CVE-2026-69684 | MED 5.5 | microsoft windows_10_1607 Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69351 | MED 5.5 | microsoft windows_10_1607 Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69339 | MED 5.5 | microsoft windows_11_24h2 Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68873 | MED 5.5 | microsoft windows_11_23h2 Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-64392 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file unlink and t | 0.5% | — |