IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-4523 HIGH 7.8 ibm db2_high_performance_unload_load IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481. 0.4% —
CVE-2019-12454 HIGH 7.8 linux linux_kernel An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. NOTE: The vendor disputes th 0.4% —
CVE-2018-16276 HIGH 7.8 canonical ubuntu_linux An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges 0.4% —
CVE-2018-1487 HIGH 8.4 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared librar 0.4% —
CVE-2014-4171 MED 4.7 canonical ubuntu_linux mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demo 0.4% —
CVE-2013-1819 MED 4.6 linux linux_kernel The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leve 0.4% —
CVE-2011-1169 HIGH 7.2 linux linux_kernel Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a craft 0.4% —
CVE-2001-1397 LOW 2.1 linux linux_kernel The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory. 0.4% —
CVE-2001-1396 LOW 3.6 linux linux_kernel Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact. 0.4% —
CVE-2001-1395 LOW 3.6 linux linux_kernel Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact. 0.4% —
CVE-2026-78451 MED 6.8 microsoft windows_10_1809 Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-69706 HIGH 7.1 microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network. 0.4% —
CVE-2026-69536 HIGH 7.1 microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0.4% —
CVE-2026-65657 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-66236 HIGH 7.5 apache airflow Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not cle 0.4% —
CVE-2026-26117 HIGH 7.8 microsoft arc_enabled_servers_azure_connected_machine_agent Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-13630 HIGH 8.8 google chrome Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2024-52928 CRIT 9.6 thebrowser arc Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website. 0.4% —
CVE-2025-20183 MED 5.8 cisco asyncos A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious fil 0.4% —
CVE-2025-21676 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but did not handle the case when it returned NULL. There was a WARN_ON(!new_ 0.4% —
CVE-2024-44973 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm, slub: do not call do_slab_free for kfence object In 782f8906f805 the freeing of kfence objects was moved from deep inside do_slab_free to the wrapper functions outside. This is a nice ch 0.4% —
CVE-2024-20737 MED 5.5 adobe after_effects After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue 0.4% —
CVE-2020-36767 HIGH 7.5 vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data. 0.4% —
CVE-2023-20230 MED 5.4 cisco application_policy_infrastructure_controller A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by 0.4% —
CVE-2023-28262 HIGH 7.8 microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability 0.4% —