58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1630 | MED 5.5 | cisco integrated_management_controller A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to in | 0.3% | — |
| CVE-2019-3593 | HIGH 7.5 | mcafee total_protection Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without per | 0.3% | — |
| CVE-2016-2545 | MED 5.1 | linux linux_kernel The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a certain linked list, which allows local users to cause a denial of service (race condition and system crash) via a crafted ioctl call. | 0.3% | — |
| CVE-2014-7989 | MED 6.8 | cisco b200_m3 Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176. | 0.3% | — |
| CVE-2008-1361 | MED 6.8 | vmware ace VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges vi | 0.3% | — |
| CVE-2007-4998 | MED 6.9 | linux linux_kernel cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination. | 0.3% | — |
| CVE-2007-5093 | MED 4.0 | linux linux_kernel The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in kh | 0.3% | — |
| CVE-2026-64093 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming i | 0.3% | — |
| CVE-2026-41728 | HIGH 7.5 | vmware spring_data_rest Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 throug | 0.3% | — |
| CVE-2026-9940 | HIGH 8.8 | google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-8531 | HIGH 8.8 | google chrome Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-43062 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() l2cap_ecred_reconf_rsp() casts the incoming data to struct l2cap_ecred_conn_rsp (the ECRED *connection* response, 8 bytes wit | 0.3% | — |
| CVE-2026-7339 | HIGH 8.8 | google chrome Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-35199 | MED 6.1 | microsoft symcrypt SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with | 0.3% | — |
| CVE-2025-59202 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55689 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55686 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55685 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55331 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53717 | HIGH 7.0 | microsoft windows_11_22h2 Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-50174 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-23336 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfigured model. A successful exploit of this vulnerability might lead to denial of service. | 0.3% | — |
| CVE-2024-58239 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: | 0.3% | — |
| CVE-2023-32249 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest. | 0.3% | — |
| CVE-2019-6697 | MED 5.3 | fortinet fortios An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate | 0.3% | — |