IT
58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-42834 HIGH 7.8 microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.4% —
CVE-2026-43490 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header 0.4% —
CVE-2026-40360 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-27928 HIGH 8.7 microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. 0.4% —
CVE-2026-25228 MED 5.0 signalk signal_k_server Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and dir 0.4% —
CVE-2026-20923 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59242 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55701 HIGH 7.8 microsoft windows_10_1507 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55695 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. 0.4% —
CVE-2025-38123 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix napi rx poll issue When driver handles the napi rx polling requests, the netdev might have been released by the dellink logic triggered by the disconnect operation on us 0.4% —
CVE-2025-24497 HIGH 7.5 f5 big-ip_policy_enforcement_manager When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-24326 HIGH 7.5 f5 big-ip_application_security_manager When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-23412 HIGH 7.5 f5 big-ip_access_policy_manager When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-22846 HIGH 7.5 f5 big-ip_access_policy_manager When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.   Note: Software versions which have reached End of Technical Support (EoT 0.4% —
CVE-2025-21087 HIGH 7.5 f5 big-ip_access_policy_manager When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical S 0.4% —
CVE-2025-20058 HIGH 7.5 f5 big-ip_access_policy_manager When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-20045 HIGH 7.5 f5 big-ip_access_policy_manager When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  N 0.4% —
CVE-2024-56632 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix the memleak while create new ctrl failed Now while we create new ctrl failed, we have not free the tagset occupied by admin_q, here try to fix it. 0.4% —
CVE-2024-11112 HIGH 8.8 google chrome Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2024-47535 MED 5.5 netty netty Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an 0.4% —
CVE-2024-40911 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Lock wiphy in cfg80211_get_station Wiphy should be locked before calling rdev_get_station() (see lockdep assert in ieee80211_get_station()). This fixes the following kernel 0.4% —
CVE-2023-49107 MED 5.3 hitachi device_manager Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04. 0.4% —
CVE-2023-21594 HIGH 7.8 adobe incopy Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th 0.4% —
CVE-2021-44023 HIGH 7.1 trendmicro antivirus\+_security_2021 A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which 0.4% —
CVE-2020-35519 HIGH 7.8 linux linux_kernel An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a sys 0.4% —