58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-3228 | LOW 2.1 | canonical ubuntu_linux The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain | 0.4% | — |
| CVE-2005-2681 | HIGH 7.2 | cisco ips_sensor_software Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors. | 0.4% | — |
| CVE-2004-0887 | HIGH 7.2 | linux linux_kernel SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges. | 0.4% | — |
| CVE-2026-20353 | CRIT 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.4% | — |
| CVE-2026-72945 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-72937 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69794 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69770 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69741 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69672 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69618 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69353 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62871 | HIGH 7.8 | microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-68079 | CRIT 9.8 | apache cxf In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization co | 0.4% | — |
| CVE-2026-53253 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a short BNEP SDU. bnep_rx_frame() reads the packet type byte immediately and, for control packets, reads the control | 0.4% | — |
| CVE-2026-9126 | HIGH 8.8 | google chrome Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2026-9118 | HIGH 8.8 | google chrome Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-9112 | HIGH 8.8 | google chrome Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-5278 | HIGH 8.8 | google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2024-53141 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefor | 0.4% | — |
| CVE-2023-38217 | MED 5.5 | adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit | 0.4% | — |
| CVE-2023-25874 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25868 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25864 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-22243 | HIGH 7.8 | adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact | 0.4% | — |