58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-6546 | LOW 1.9 | linux linux_kernel The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. | 0.4% | — |
| CVE-2013-0290 | MED 4.9 | linux linux_kernel The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted applica | 0.4% | — |
| CVE-2010-4346 | LOW 2.1 | linux linux_kernel The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer derefer | 0.4% | — |
| CVE-2005-3660 | MED 4.9 | linux linux_kernel Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to fini | 0.4% | — |
| CVE-2004-0997 | MED 4.6 | linux linux_kernel Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors. | 0.4% | — |
| CVE-2026-69690 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-19306 | HIGH 7.7 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload | 0.4% | — |
| CVE-2026-41729 | HIGH 8.1 | vmware spring_data_rest Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key | 0.4% | — |
| CVE-2026-45602 | CRIT 9.1 | microsoft windows_10_1607 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | 0.4% | — |
| CVE-2026-3931 | HIGH 8.8 | google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2025-62572 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62571 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62467 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62464 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62462 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62461 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55233 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60720 | HIGH 7.8 | microsoft windows_10_1607 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60713 | HIGH 7.8 | microsoft windows_server_2016 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59505 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2023-53360 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. | 0.4% | — |
| CVE-2025-29795 | HIGH 7.8 | microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24312 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization. Note: Software versions which have re | 0.4% | — |
| CVE-2025-21372 | HIGH 7.8 | microsoft windows_11_24h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-53954 | HIGH 7.8 | adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 0.4% | — |