58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-24857 | MED 4.6 | debian debian_linux A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service. | 0.3% | — |
| CVE-2023-6111 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument syn | 0.3% | — |
| CVE-2023-44330 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 0.3% | — |
| CVE-2023-36833 | MED 6.5 | juniper junos_os_evolved A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36MR, and PTX10004, PTX10008, PTX10016 with LC1201/1202 allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). The | 0.3% | — |
| CVE-2022-49468 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: thermal/core: Fix memory leak in __thermal_cooling_device_register() I got memory leak as follows when doing fault injection test: unreferenced object 0xffff888010080000 (size 264312): co | 0.3% | — |
| CVE-2022-4662 | MED 5.5 | linux linux_kernel A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local user could use this flaw to crash the system. | 0.3% | — |
| CVE-2022-41100 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-41045 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-2961 | HIGH 7.0 | fedoraproject fedora A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th | 0.3% | — |
| CVE-2021-20515 | MED 6.7 | ibm informix_dynamic_server IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force I | 0.3% | — |
| CVE-2020-3404 | HIGH 7.8 | cisco ios_xe A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges. | 0.3% | — |
| CVE-2019-20934 | MED 5.3 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c. | 0.3% | — |
| CVE-2017-2330 | MED 6.2 | juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create pr | 0.3% | — |
| CVE-2016-1271 | HIGH 7.8 | juniper junos Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow | 0.3% | — |
| CVE-2015-3339 | MED 6.2 | debian debian_linux Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid | 0.3% | — |
| CVE-2015-0664 | MED 4.3 | cisco anyconnect_secure_mobility_client The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195. | 0.3% | — |
| CVE-2013-0310 | MED 6.6 | linux linux_kernel The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsock | 0.3% | — |
| CVE-2026-72967 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72965 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72953 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72946 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72944 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71345 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-70584 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70569 | HIGH 7.8 | microsoft windows_11_23h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |