IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-48632 HIGH 7.8 adobe after_effects Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti 0.3% —
CVE-2022-34238 MED 5.5 adobe acrobat Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t 0.3% —
CVE-2022-30703 HIGH 7.8 trendmicro security Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be c 0.3% —
CVE-2021-47611 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mac80211: validate extended element ID is present Before attempting to parse an extended element, verify that the extended element ID is present. 0.3% —
CVE-2021-45095 MED 5.5 debian debian_linux pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. 0.3% —
CVE-2020-15852 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of 0.3% —
CVE-2019-11096 MED 5.5 intel ethernet_i218_adapter_driver Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow an authenticated user to potentially enable information disclosure via local access. 0.3% —
CVE-2017-7794 HIGH 7.8 mozilla firefox On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux ope 0.3% —
CVE-2017-6679 MED 6.4 cisco umbrella_virtual_appliance The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily levera 0.3% —
CVE-2017-4900 MED 5.5 vmware workstation_player VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs. 0.3% —
CVE-2017-12340 MED 4.2 cisco nx-os A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device 0.3% —
CVE-2014-1444 LOW 1.7 linux linux_kernel The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capabil 0.3% —
CVE-2013-1957 MED 4.7 linux linux_kernel The clone_mnt function in fs/namespace.c in the Linux kernel before 3.8.6 does not properly restrict changes to the MNT_READONLY flag, which allows local users to bypass an intended read-only property of a filesystem by leveraging a separate mount namespace. 0.3% —
CVE-2012-1796 HIGH 7.2 ibm db2 Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors. 0.3% —
CVE-2006-2662 MED 4.6 vmware server VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges. 0.3% —
CVE-1999-1285 LOW 2.1 linux linux_kernel Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. 0.3% —
CVE-2026-70289 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69638 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.3% —
CVE-2026-69479 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.3% —
CVE-2026-6296 CRIT 9.6 google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3% —
CVE-2026-55000 MED 6.4 microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.3% —
CVE-2026-41841 MED 5.9 vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. 0.3% —
CVE-2026-40404 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.3% —
CVE-2026-3779 HIGH 7.8 foxit pdf_editor The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary cod 0.3% —
CVE-2026-32079 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.3% —