IT
58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.415 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2001-1391 MED 5.5 linux linux_kernel Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory. 0.4% —
CVE-2026-9973 HIGH 8.8 google chrome Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-6052 MED 6.5 ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. 0.4% —
CVE-2026-45490 HIGH 7.8 microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-20150 HIGH 8.8 cisco roomos As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally d 0.4% —
CVE-2025-67604 MED 5.3 fortinet fortianalyzer A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7 0.4% —
CVE-2025-59255 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59207 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-58728 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55677 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55339 HIGH 7.8 microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55317 HIGH 7.8 microsoft autoupdate Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-55245 HIGH 7.8 microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-54115 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-50175 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-50152 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-0440 MED 6.5 google chrome Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2025-0130 HIGH 7.5 paloaltonetworks pan-os A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate 0.4% —
CVE-2024-49526 HIGH 7.8 adobe animate Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.4% —
CVE-2024-41761 MED 5.3 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query. 0.4% —
CVE-2024-39518 HIGH 7.5 juniper junos A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS). Wh 0.4% —
CVE-2023-47078 MED 5.5 adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ 0.4% —
CVE-2023-47061 MED 5.5 adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ 0.4% —
CVE-2022-34865 MED 4.8 f5 big-ip_access_policy_manager In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reac 0.4% —
CVE-2022-22008 HIGH 7.8 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 0.4% —