IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1630 MED 5.5 cisco integrated_management_controller A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to in 0.3% —
CVE-2019-3593 HIGH 7.5 mcafee total_protection Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without per 0.3% —
CVE-2016-2545 MED 5.1 linux linux_kernel The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a certain linked list, which allows local users to cause a denial of service (race condition and system crash) via a crafted ioctl call. 0.3% —
CVE-2014-7989 MED 6.8 cisco b200_m3 Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176. 0.3% —
CVE-2008-1361 MED 6.8 vmware ace VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges vi 0.3% —
CVE-2007-4998 MED 6.9 linux linux_kernel cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination. 0.3% —
CVE-2007-5093 MED 4.0 linux linux_kernel The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in kh 0.3% —
CVE-2026-64093 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming i 0.3% —
CVE-2026-41728 HIGH 7.5 vmware spring_data_rest Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 throug 0.3% —
CVE-2026-9940 HIGH 8.8 google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3% —
CVE-2026-8531 HIGH 8.8 google chrome Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3% —
CVE-2026-43062 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() l2cap_ecred_reconf_rsp() casts the incoming data to struct l2cap_ecred_conn_rsp (the ECRED *connection* response, 8 bytes wit 0.3% —
CVE-2026-7339 HIGH 8.8 google chrome Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.3% —
CVE-2026-35199 MED 6.1 microsoft symcrypt SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with 0.3% —
CVE-2025-59202 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-55689 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-55686 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-55685 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-55331 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-53717 HIGH 7.0 microsoft windows_11_22h2 Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-50174 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-23336 MED 4.4 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfigured model. A successful exploit of this vulnerability might lead to denial of service. 0.3% —
CVE-2024-58239 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: 0.3% —
CVE-2023-32249 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest. 0.3% —
CVE-2019-6697 MED 5.3 fortinet fortios An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate 0.3% —