IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2015-8839 MED 5.1 canonical ubuntu_linux Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punchi 0.4% —
CVE-2012-4108 MED 6.8 cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-system commands via crafted parameters to a file-related command, aka Bug ID CSCtq86554. 0.4% —
CVE-2012-2669 LOW 2.1 linux linux_kernel The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message. 0.4% —
CVE-2012-1097 HIGH 7.8 linux linux_kernel The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact vi 0.4% —
CVE-2010-0530 LOW 2.1 apple quicktime Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory. 0.4% —
CVE-2009-0024 HIGH 7.2 linux linux_kernel The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap function 0.4% —
CVE-2008-3485 HIGH 7.2 citrix metaframe_presentation_server Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. 0.4% —
CVE-2007-6049 HIGH 7.2 ibm db2_universal_database Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root. 0.4% —
CVE-2007-2480 MED 4.6 linux linux_kernel The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local 0.4% —
CVE-2026-69403 MED 5.5 microsoft windows_10_1607 Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-69267 MED 6.5 microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-62775 MED 5.5 microsoft windows_11_26h1 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-59135 MED 5.5 microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-18972 CRIT 9.6 An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. 0.4% —
CVE-2026-13445 HIGH 8.1 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor 0.4% —
CVE-2026-58545 MED 5.5 microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-50312 MED 4.7 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-49167 MED 4.7 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-33103 MED 5.5 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-32214 MED 5.5 microsoft windows_10_1607 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0.4% —
CVE-2025-58738 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58736 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58734 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58733 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58731 HIGH 7.0 microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —