IT
58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-4897 MED 6.9 vmware movie_decoder Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory. 0.4% —
CVE-2005-0207 LOW 2.1 conectiva linux Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT. 0.4% —
CVE-1999-0317 HIGH 7.2 linux linux_kernel Buffer overflow in Linux su command gives root access to local users. 0.4% —
CVE-1999-0330 HIGH 7.2 linux linux_kernel Linux bdash game has a buffer overflow that allows local users to gain root access. 0.4% —
CVE-2026-71348 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-9138 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input 0.4% —
CVE-2026-66908 HIGH 7.5 apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe 0.4% —
CVE-2026-62699 MED 6.8 microsoft windows_10_1607 Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-65432 HIGH 7.5 apache cxf Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declara 0.4% —
CVE-2026-64444 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP 0.4% —
CVE-2026-64443 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a m 0.4% —
CVE-2026-50377 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-9154 HIGH 7.1 gnu sed Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter. 0.4% —
CVE-2026-43341 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the trace length in a u8. With bit 22 enabled and the largest schema 0.4% —
CVE-2026-27912 HIGH 8.0 microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. 0.4% —
CVE-2026-30911 HIGH 8.1 apache airflow Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instanc 0.4% —
CVE-2025-13633 HIGH 8.8 google chrome Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2024-41768 MED 6.5 ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. 0.4% —
CVE-2024-8687 HIGH 7.1 paloaltonetworks globalprotect An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or pass 0.4% —
CVE-2024-30057 MED 5.4 microsoft edge Microsoft Edge for iOS Spoofing Vulnerability 0.4% —
CVE-2021-43753 HIGH 7.8 adobe lightroom Adobe Lightroom versions 4.4 (and earlier) are affected by a use-after-free vulnerability in the processing of parsing TIF files that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malici 0.4% —
CVE-2023-20229 HIGH 7.1 cisco duo_device_health_application A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. Thi 0.4% —
CVE-2023-20224 HIGH 7.8 cisco thousandeyes_enterprise_agent A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validat 0.4% —
CVE-2022-38448 HIGH 7.8 adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0.4% —
CVE-2022-38447 HIGH 7.8 adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0.4% —