58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28375 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308. | 0.3% | — |
| CVE-2020-5892 | MED 6.7 | f5 big-ip_access_policy_manager In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory. | 0.3% | — |
| CVE-2018-6236 | HIGH 7.0 | trendmicro antivirus\+ A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver | 0.3% | — |
| CVE-2016-1360 | HIGH 7.1 | cisco prime_lan_management_solution Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390. | 0.3% | — |
| CVE-2012-4081 | MED 4.6 | cisco unified_computing_system MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734. | 0.3% | — |
| CVE-2026-7345 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hig | 0.3% | — |
| CVE-2026-69900 | HIGH 7.8 | microsoft windows_10_21h2 Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69731 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69369 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-69288 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-65105 | HIGH 8.1 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of servi | 0.3% | — |
| CVE-2026-41728 | HIGH 7.5 | vmware spring_data_rest Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 throug | 0.3% | — |
| CVE-2026-30793 | CRIT 9.8 | rustdesk rustdesk Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with progra | 0.3% | — |
| CVE-2026-14525 | CRIT 9.4 | ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | 0.3% | — |
| CVE-2026-14113 | CRIT 9.6 | google chrome Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-13861 | CRIT 9.6 | google chrome Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-13859 | CRIT 9.6 | google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-13854 | CRIT 9.6 | google chrome Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-13853 | CRIT 9.6 | google chrome Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-11117 | HIGH 8.8 | google chrome Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2025-55670 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva | 0.3% | — |
| CVE-2025-54838 | MED 6.8 | fortinet fortiportal An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests. | 0.3% | — |
| CVE-2025-54805 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End o | 0.3% | — |
| CVE-2025-53608 | MED 4.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 0.3% | — |
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0.3% | — |