58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-8839 | MED 5.1 | canonical ubuntu_linux Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punchi | 0.4% | — |
| CVE-2012-4108 | MED 6.8 | cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-system commands via crafted parameters to a file-related command, aka Bug ID CSCtq86554. | 0.4% | — |
| CVE-2012-2669 | LOW 2.1 | linux linux_kernel The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message. | 0.4% | — |
| CVE-2012-1097 | HIGH 7.8 | linux linux_kernel The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact vi | 0.4% | — |
| CVE-2010-0530 | LOW 2.1 | apple quicktime Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory. | 0.4% | — |
| CVE-2009-0024 | HIGH 7.2 | linux linux_kernel The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap function | 0.4% | — |
| CVE-2008-3485 | HIGH 7.2 | citrix metaframe_presentation_server Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. | 0.4% | — |
| CVE-2007-6049 | HIGH 7.2 | ibm db2_universal_database Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root. | 0.4% | — |
| CVE-2007-2480 | MED 4.6 | linux linux_kernel The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local | 0.4% | — |
| CVE-2026-69403 | MED 5.5 | microsoft windows_10_1607 Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69267 | MED 6.5 | microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62775 | MED 5.5 | microsoft windows_11_26h1 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59135 | MED 5.5 | microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-18972 | CRIT 9.6 | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. | 0.4% | — |
| CVE-2026-13445 | HIGH 8.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor | 0.4% | — |
| CVE-2026-58545 | MED 5.5 | microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-50312 | MED 4.7 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-49167 | MED 4.7 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-33103 | MED 5.5 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-32214 | MED 5.5 | microsoft windows_10_1607 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2025-58738 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58736 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58734 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58733 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58731 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |