IT
58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2007-2525 MED 4.9 linux linux_kernel Memory leak in the PPP over Ethernet (PPPoE) socket implementation in the Linux kernel before 2.6.21-git8 allows local users to cause a denial of service (memory consumption) by creating a socket using connect, and releasing it before the PPPIOCGCHAN ioctl is 0.4% —
CVE-2007-1592 MED 4.9 linux linux_kernel net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, a 0.4% —
CVE-2002-1976 LOW 2.1 linux linux_kernel ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstra 0.4% —
CVE-2026-20352 HIGH 8.6 A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIU 0.4% —
CVE-2026-20154 HIGH 8.6 A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause h 0.4% —
CVE-2026-87648 HIGH 8.3 google chrome Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Med 0.4% —
CVE-2026-87524 HIGH 8.3 google chrome Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High 0.4% —
CVE-2026-83501 MED 5.5 microsoft windows_11_23h2 Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-78454 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-70290 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-70145 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69808 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69609 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69568 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69527 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69457 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69390 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69369 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69344 MED 5.5 microsoft windows_10_21h2 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69343 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69318 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69288 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69286 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-59270 CRIT 9.4 vmware spring_security Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 0.4% —
CVE-2026-68817 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4% —