58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.646 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-64398 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after checking | 0.7% | — |
| CVE-2026-47629 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. | 0.7% | — |
| CVE-2026-47628 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | 0.7% | — |
| CVE-2026-13473 | HIGH 8.1 | ibm storage_protect IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary co | 0.7% | — |
| CVE-2025-62220 | HIGH 8.8 | microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-53156 | MED 5.5 | microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-21346 | HIGH 7.1 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-43625 | HIGH 8.1 | microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-41073 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear the RQF_SPEC | 0.7% | — |
| CVE-2024-1552 | HIGH 7.5 | debian debian_linux Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | 0.7% | — |
| CVE-2024-0136 | HIGH 7.6 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit i | 0.7% | — |
| CVE-2023-39176 | MED 5.8 | linux linux_kernel A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacke | 0.7% | — |
| CVE-2023-38041 | HIGH 7.0 | ivanti secure_access_client A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | 0.7% | — |
| CVE-2023-34058 | HIGH 7.1 | debian debian_linux VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target vi | 0.7% | — |
| CVE-2022-49084 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: qede: confirm skb is allocated before using qede_build_skb() assumes build_skb() always works and goes straight to skb_reserve(). However, build_skb() can fail under memory pressure. This re | 0.7% | — |
| CVE-2022-3734 | MED 6.3 | redis redis A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be initiated r | 0.7% | — |
| CVE-2022-2160 | MED 6.5 | fedoraproject fedora Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML pa | 0.7% | — |
| CVE-2020-36516 | MED 5.9 | linux linux_kernel An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session. | 0.7% | — |
| CVE-2017-7518 | MED 5.5 | canonical ubuntu_linux A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process insi | 0.7% | — |
| CVE-2017-7340 | MED 6.1 | fortinet fortiportal A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality. | 0.7% | — |
| CVE-2016-8658 | MED 6.1 | linux linux_kernel Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified othe | 0.7% | — |
| CVE-2016-8414 | MED 4.7 | google android An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising | 0.7% | — |
| CVE-2025-58136 | HIGH 7.5 | apache traffic_server A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A wo | 0.7% | — |
| CVE-2024-38047 | HIGH 7.8 | microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36551 | MED 4.3 | fortinet fortisiem A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. | 0.7% | — |