IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-27046 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfp: flower: handle acti_netdevs allocation failure The kmalloc_array() in nfp_fl_lag_do_work() will return null, if the physical memory has run out. As a result, if we dereference the acti_ 0.3%
CVE-2023-53491 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: start_kernel: Add __no_stack_protector function attribute Back during the discussion of commit a9a3ed1eff36 ("x86: Fix early boot crash on gcc-10, third try") we discussed the need for a fun 0.3%
CVE-2023-38268 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260585. 0.3%
CVE-2022-49720 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: block: Fix handling of offline queues in blk_mq_alloc_request_hctx() This patch prevents that test nvme/004 triggers the following: UBSAN: array-index-out-of-bounds in block/blk-mq.h:135:9 0.3%
CVE-2022-49568 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of two callbacks: 1) destroy() which is called when the VM is being destroyed; 2) release() which is called wh 0.3%
CVE-2022-49520 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: compat: Do not treat syscall number as ESR_ELx for a bad syscall If a compat process tries to execute an unknown system call above the __ARM_NR_COMPAT_END number, the kernel sends a S 0.3%
CVE-2022-49508 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: elan: Fix potential double free in elan_input_configured 'input' is a managed resource allocated with devm_input_allocate_device(), so there is no need to call input_free_device() expli 0.3%
CVE-2022-49410 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tracing: Fix potential double free in create_var_ref() In create_var_ref(), init_var_ref() is called to initialize the fields of variable ref_field, which is allocated in the previous functi 0.3%
CVE-2022-49385 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF. To fix it, we need t 0.3%
CVE-2022-45453 HIGH 7.5 acronis cyber_protect TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. 0.3%
CVE-2022-22983 MED 5.9 vmware workstation VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote 0.3%
CVE-2022-0171 MED 5.5 debian debian_linux A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualizati 0.3%
CVE-2012-1943 MED 6.9 mozilla firefox Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory. 0.3%
CVE-2010-1805 MED 6.9 apple safari Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded 0.3%
CVE-2026-68851 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-62887 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-58631 HIGH 7.8 microsoft windows_admin_center Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. 0.3%
CVE-2026-58540 HIGH 7.8 microsoft windows_10_1607 Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-57107 HIGH 7.8 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-57088 HIGH 7.8 microsoft windows_10_1809 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55014 HIGH 7.8 microsoft remote_help Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55006 HIGH 7.8 microsoft exchange_server Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55001 HIGH 7.8 microsoft windows_10_1607 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50465 HIGH 7.1 microsoft windows_11_24h2 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-50423 HIGH 7.8 microsoft windows_10_21h2 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%