58.139 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-7995 | MED 4.7 | canonical ubuntu_linux Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devic | 0.3% | — |
| CVE-2017-12317 | MED 6.7 | cisco advanced_malware_protection The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the conne | 0.3% | — |
| CVE-2014-0684 | MED 4.6 | cisco nexus_7000 Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136. | 0.3% | — |
| CVE-2013-1196 | MED 6.8 | cisco application_networking_manager The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Un | 0.3% | — |
| CVE-2013-1125 | MED 6.8 | cisco application_networking_manager The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaborati | 0.3% | — |
| CVE-2012-4121 | MED 6.8 | cisco nx-os Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, CSCts56565, CSCts56570, and CSCts56574. | 0.3% | — |
| CVE-2026-9873 | HIGH 8.8 | google chrome Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-8529 | HIGH 8.8 | google chrome Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-68831 | MED 5.5 | microsoft windows_10_1607 Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-57028 | HIGH 7.3 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which shoul | 0.3% | — |
| CVE-2026-4463 | HIGH 8.8 | google chrome Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-42901 | CRIT 10.0 | microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0.3% | — |
| CVE-2026-20332 | CRIT 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond | 0.3% | — |
| CVE-2026-20279 | CRIT 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte | 0.3% | — |
| CVE-2026-12441 | HIGH 8.8 | google chrome Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-11047 | CRIT 9.6 | google chrome Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-11042 | HIGH 8.8 | google chrome Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2025-62631 | MED 5.6 | fortinet fortios An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN sessio | 0.3% | — |
| CVE-2025-44016 | HIGH 8.8 | teamviewer digital_employee_experience A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a mali | 0.3% | — |
| CVE-2025-40039 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session. Access to this list is intended to be protected by 'sess->r | 0.3% | — |
| CVE-2025-37881 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL point | 0.3% | — |
| CVE-2025-37872 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix memory leak in txgbe_probe() error path When txgbe_sw_init() is called, memory is allocated for wx->rss_key in wx_init_rss_key(). However, in txgbe_probe() function, the subs | 0.3% | — |
| CVE-2025-37862 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: HID: pidff: Fix null pointer dereference in pidff_find_fields This function triggered a null pointer dereference if used to search for a report that isn't implemented on the device. This hap | 0.3% | — |
| CVE-2025-37859 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: page_pool: avoid infinite loop to schedule delayed worker We noticed the kworker in page_pool_release_retry() was waken up repeatedly and infinitely in production because of the buggy driver | 0.3% | — |
| CVE-2025-37858 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fs/jfs: Prevent integer overflow in AG size calculation The JFS filesystem calculates allocation group (AG) size using 1 << l2agsize in dbExtendFS(). When l2agsize exceeds 31 (possible with | 0.3% | — |