58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-34362 | MED 4.6 | ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache po | 0.4% | — |
| CVE-2021-4202 | HIGH 7.0 | linux linux_kernel A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to | 0.4% | — |
| CVE-2022-22938 | MED 6.5 | vmware horizon VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual ma | 0.4% | — |
| CVE-2021-38203 | MED 5.5 | linux linux_kernel btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info. | 0.4% | — |
| CVE-2020-29368 | HIGH 7.0 | linux linux_kernel An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1. | 0.4% | — |
| CVE-2019-19694 | MED 4.7 | trendmicro antivirus_\+_security_2019 The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the produc | 0.4% | — |
| CVE-2018-16177 | HIGH 7.8 | ntt-west fall_creators_update Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 0.4% | — |
| CVE-2016-9806 | HIGH 7.8 | linux linux_kernel Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system | 0.4% | — |
| CVE-2016-8826 | MED 5.5 | nvidia gpu_driver All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service. | 0.4% | — |
| CVE-2016-4440 | HIGH 7.8 | linux linux_kernel arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code o | 0.4% | — |
| CVE-2015-2672 | MED 5.5 | linux linux_kernel The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a | 0.4% | — |
| CVE-2013-7348 | MED 4.6 | linux linux_kernel Double free vulnerability in the ioctx_alloc function in fs/aio.c in the Linux kernel before 3.12.4 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via vectors involving an error condition in the aio_set | 0.4% | — |
| CVE-2013-2894 | MED 4.7 | linux linux_kernel drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a cr | 0.4% | — |
| CVE-2003-0739 | MED 4.6 | vmware workstation VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack. | 0.4% | — |
| CVE-2026-69638 | HIGH 8.4 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-69479 | HIGH 8.4 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-69328 | HIGH 7.8 | microsoft windows_10_1607 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-72971 | MED 5.5 | microsoft windows_11_26h1 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | 0.4% | — |
| CVE-2026-66310 | HIGH 7.7 | microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-54128 | HIGH 8.4 | microsoft windows_10_1607 Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-54122 | HIGH 8.4 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-49798 | CRIT 9.3 | microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-47635 | HIGH 8.4 | microsoft office_2024 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45474 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45472 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |