58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-1237 | LOW 2.1 | linux linux_kernel Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors. | 0.4% | — |
| CVE-1999-1126 | LOW 2.1 | cisco resource_manager Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug. | 0.4% | — |
| CVE-2026-8854 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | 0.4% | — |
| CVE-2026-70317 | MED 5.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-64140 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in proc_show_files() When a SMB2 client opens a file with a durable v2 handle and then issues SMB2 SESSION_LOGOFF, session_fd_check() clears fp->tcon = NU | 0.4% | — |
| CVE-2026-58640 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-52960 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback The batch holds references to the folios (see `filemap_get_folios`, `folio_batch_release`), so we need to `folio_put` the folios we remove. Teste | 0.4% | — |
| CVE-2026-52956 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct | 0.4% | — |
| CVE-2026-50510 | HIGH 7.8 | microsoft github_copilot Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-50482 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-49790 | HIGH 7.3 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2026-49789 | HIGH 7.3 | microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-4676 | HIGH 8.8 | google chrome Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-39815 | HIGH 8.8 | fortinet fortiddos-f A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests | 0.4% | — |
| CVE-2026-26148 | HIGH 8.1 | microsoft azure_ad_ssh_login_extension_for_linux External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-26131 | HIGH 7.8 | microsoft .net Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-25604 | MED 5.4 | apache apache-airflow-providers-amazon In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML | 0.4% | — |
| CVE-2026-11662 | HIGH 8.8 | google chrome Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-0262 | HIGH 7.5 | paloaltonetworks pan-os Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not | 0.4% | — |
| CVE-2025-67706 | MED 5.6 | esri arcgis_server ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture en | 0.4% | — |
| CVE-2025-60721 | HIGH 7.8 | microsoft windows_11_24h2 Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-60716 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59514 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53789 | HIGH 7.8 | microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53681 | HIGH 7.2 | fortinet fortimail An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privil | 0.4% | — |