IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2009-3228 LOW 2.1 canonical ubuntu_linux The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain 0.4% —
CVE-2005-2681 HIGH 7.2 cisco ips_sensor_software Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors. 0.4% —
CVE-2004-0887 HIGH 7.2 linux linux_kernel SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges. 0.4% —
CVE-2026-20353 CRIT 9.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har 0.4% —
CVE-2026-72945 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-72937 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69794 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69770 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69741 MED 5.5 microsoft windows_10_21h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69672 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69618 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69353 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-62871 HIGH 7.8 microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-68079 CRIT 9.8 apache cxf In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization co 0.4% —
CVE-2026-53253 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a short BNEP SDU. bnep_rx_frame() reads the packet type byte immediately and, for control packets, reads the control 0.4% —
CVE-2026-9126 HIGH 8.8 google chrome Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2026-9118 HIGH 8.8 google chrome Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-9112 HIGH 8.8 google chrome Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-5278 HIGH 8.8 google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2024-53141 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefor 0.4% —
CVE-2023-38217 MED 5.5 adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit 0.4% —
CVE-2023-25874 HIGH 7.8 adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.4% —
CVE-2023-25868 HIGH 7.8 adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.4% —
CVE-2023-25864 HIGH 7.8 adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.4% —
CVE-2023-22243 HIGH 7.8 adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact 0.4% —