58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.465 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-29368 | HIGH 7.0 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-29364 | HIGH 7.0 | microsoft windows_10_1507 Windows Authentication Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-28216 | HIGH 7.0 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-26605 | HIGH 7.8 | linux linux_kernel In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid. | 0.4% | — |
| CVE-2023-24068 | HIGH 7.8 | signal signal-desktop Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's abili | 0.4% | — |
| CVE-2022-34248 | MED 5.5 | adobe indesign Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this v | 0.4% | — |
| CVE-2022-30687 | HIGH 7.1 | trendmicro maximum_security_2022 Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files. | 0.4% | — |
| CVE-2022-22179 | MED 6.5 | juniper junos A Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). | 0.4% | — |
| CVE-2021-29816 | MED 6.5 | ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: | 0.4% | — |
| CVE-2021-1452 | MED 6.8 | cisco ios_xe_rom_monitor A vulnerability in the ROM Monitor (ROMMON) of Cisco IOS XE Software for Cisco Catalyst IE3200, IE3300, and IE3400 Rugged Series Switches, Cisco Catalyst IE3400 Heavy Duty Series Switches, and Cisco Embedded Services 3300 Series Switches could allow an unauthe | 0.4% | — |
| CVE-2020-3514 | HIGH 8.2 | cisco secure_firewall_management_center A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. Th | 0.4% | — |
| CVE-2019-1648 | HIGH 7.8 | cisco sd-wan A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included | 0.4% | — |
| CVE-2017-18193 | MED 5.5 | linux linux_kernel fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads. | 0.4% | — |
| CVE-2017-17448 | HIGH 7.8 | linux linux_kernel net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure | 0.4% | — |
| CVE-2017-1105 | HIGH 7.1 | ibm data_server_client IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668. | 0.4% | — |
| CVE-2010-5329 | MED 5.5 | linux linux_kernel The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 relies on the count value of a v4l2_ext_controls data structure to determine a kmalloc size, which might allow local users to cause a denial of service (memory co | 0.4% | — |
| CVE-2016-10088 | HIGH 7.0 | linux linux_kernel The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use- | 0.4% | — |
| CVE-2010-1643 | MED 6.9 | linux linux_kernel mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly hav | 0.4% | — |
| CVE-2009-3624 | MED 4.6 | linux kernel The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service ( | 0.4% | — |
| CVE-2026-20072 | MED 4.9 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerabili | 0.4% | — |
| CVE-2026-4674 | HIGH 8.8 | google chrome Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-3926 | HIGH 8.8 | google chrome Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2026-3920 | HIGH 8.8 | google chrome Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-22256 | MED 6.3 | fortinet fortipam A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP r | 0.4% | — |
| CVE-2025-37777 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __smb2_lease_break_noti() Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed | 0.4% | — |