IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-24857 MED 4.6 debian debian_linux A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service. 0.3% —
CVE-2023-6111 HIGH 7.8 linux linux_kernel A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument syn 0.3% —
CVE-2023-44330 HIGH 7.8 adobe photoshop Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 0.3% —
CVE-2023-36833 MED 6.5 juniper junos_os_evolved A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36MR, and PTX10004, PTX10008, PTX10016 with LC1201/1202 allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). The 0.3% —
CVE-2022-49468 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: thermal/core: Fix memory leak in __thermal_cooling_device_register() I got memory leak as follows when doing fault injection test: unreferenced object 0xffff888010080000 (size 264312): co 0.3% —
CVE-2022-4662 MED 5.5 linux linux_kernel A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local user could use this flaw to crash the system. 0.3% —
CVE-2022-41100 HIGH 7.8 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0.3% —
CVE-2022-41045 HIGH 7.8 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0.3% —
CVE-2022-2961 HIGH 7.0 fedoraproject fedora A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th 0.3% —
CVE-2021-20515 MED 6.7 ibm informix_dynamic_server IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force I 0.3% —
CVE-2020-3404 HIGH 7.8 cisco ios_xe A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges. 0.3% —
CVE-2019-20934 MED 5.3 linux linux_kernel An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c. 0.3% —
CVE-2017-2330 MED 6.2 juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create pr 0.3% —
CVE-2016-1271 HIGH 7.8 juniper junos Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow 0.3% —
CVE-2015-3339 MED 6.2 debian debian_linux Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid 0.3% —
CVE-2015-0664 MED 4.3 cisco anyconnect_secure_mobility_client The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195. 0.3% —
CVE-2013-0310 MED 6.6 linux linux_kernel The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsock 0.3% —
CVE-2026-72967 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72965 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72953 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72946 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72944 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-71345 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-70584 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-70569 HIGH 7.8 microsoft windows_11_23h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. 0.3% —