58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-4897 | MED 6.9 | vmware movie_decoder Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory. | 0.4% | — |
| CVE-2005-0207 | LOW 2.1 | conectiva linux Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT. | 0.4% | — |
| CVE-1999-0317 | HIGH 7.2 | linux linux_kernel Buffer overflow in Linux su command gives root access to local users. | 0.4% | — |
| CVE-1999-0330 | HIGH 7.2 | linux linux_kernel Linux bdash game has a buffer overflow that allows local users to gain root access. | 0.4% | — |
| CVE-2026-71348 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-9138 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input | 0.4% | — |
| CVE-2026-66908 | HIGH 7.5 | apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe | 0.4% | — |
| CVE-2026-62699 | MED 6.8 | microsoft windows_10_1607 Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-65432 | HIGH 7.5 | apache cxf Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declara | 0.4% | — |
| CVE-2026-64444 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP | 0.4% | — |
| CVE-2026-64443 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a m | 0.4% | — |
| CVE-2026-50377 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-9154 | HIGH 7.1 | gnu sed Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter. | 0.4% | — |
| CVE-2026-43341 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the trace length in a u8. With bit 22 enabled and the largest schema | 0.4% | — |
| CVE-2026-27912 | HIGH 8.0 | microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2026-30911 | HIGH 8.1 | apache airflow Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instanc | 0.4% | — |
| CVE-2025-13633 | HIGH 8.8 | google chrome Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2024-41768 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. | 0.4% | — |
| CVE-2024-8687 | HIGH 7.1 | paloaltonetworks globalprotect An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or pass | 0.4% | — |
| CVE-2024-30057 | MED 5.4 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 0.4% | — |
| CVE-2021-43753 | HIGH 7.8 | adobe lightroom Adobe Lightroom versions 4.4 (and earlier) are affected by a use-after-free vulnerability in the processing of parsing TIF files that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malici | 0.4% | — |
| CVE-2023-20229 | HIGH 7.1 | cisco duo_device_health_application A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. Thi | 0.4% | — |
| CVE-2023-20224 | HIGH 7.8 | cisco thousandeyes_enterprise_agent A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validat | 0.4% | — |
| CVE-2022-38448 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.4% | — |
| CVE-2022-38447 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.4% | — |