58.412 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.412 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-2678 | MED 4.7 | fedoraproject fedora The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a | 0.4% | — |
| CVE-2012-0038 | MED 5.5 | linux linux_kernel Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow. | 0.4% | — |
| CVE-2011-2518 | MED 4.9 | linux linux_kernel The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unsp | 0.4% | — |
| CVE-2011-2182 | HIGH 7.2 | linux linux_kernel The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive | 0.4% | — |
| CVE-2026-87648 | HIGH 8.3 | google chrome Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Med | 0.4% | — |
| CVE-2026-87524 | HIGH 8.3 | google chrome Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High | 0.4% | — |
| CVE-2026-83501 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-78454 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70290 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70145 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69808 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69609 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69568 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69527 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69457 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69390 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69369 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69344 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69343 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69318 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69288 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69286 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68817 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-68814 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-68812 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |