IT
58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.285 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2018-15471 HIGH 7.8 canonical ubuntu_linux An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queue 0.4% —
CVE-2017-4895 HIGH 8.8 vmware airwatch_agent Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data. 0.4% —
CVE-2017-12350 HIGH 8.2 cisco umbrella_virtual_appliance A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user crede 0.4% —
CVE-2016-8660 MED 5.5 linux linux_kernel The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implement 0.4% —
CVE-2015-0660 HIGH 7.2 cisco telepresence_server_software Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123. 0.4% —
CVE-2013-6689 MED 6.9 cisco unified_communications_manager Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229. 0.4% —
CVE-2012-4104 MED 6.6 cisco unified_computing_system Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary files via a full pathname in an image header, aka Bug ID CSCtq0 0.4% —
CVE-2010-4649 MED 6.9 linux linux_kernel Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a ce 0.4% —
CVE-2001-1273 LOW 2.1 linux linux_kernel The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt). 0.4% —
CVE-2026-69612 HIGH 7.8 microsoft windows_10_1607 Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-47631 HIGH 8.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.4% —
CVE-2026-45658 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-43345 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for IPA v5.0+ For IPA v5.0+, the event ring index field moved from CH_C_CNTXT_0 to CH_C_CNTXT_1. The v5.0 register definition intended to define 0.4% —
CVE-2026-41705 HIGH 8.6 vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 0.4% —
CVE-2026-33803 MED 6.5 juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due t 0.4% —
CVE-2026-32084 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-26134 HIGH 7.8 microsoft 365_copilot Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-24253 HIGH 8.2 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. 0.4% —
CVE-2026-23672 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4% —
CVE-2026-22742 HIGH 8.6 vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i 0.4% —
CVE-2026-21242 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-14108 HIGH 8.8 google chrome Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) 0.4% —
CVE-2025-55697 HIGH 7.8 microsoft windows_server_2022_23h2 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-38523 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy The handling of received data in the smbdirect client code involves using copy_to_iter() to copy data from the smbd_reponse struct's packet 0.4% —
CVE-2025-37959 CRIT 9.4 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't scrubbed. That can lead skb information from 0.4% —