58.415 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-1391 | MED 5.5 | linux linux_kernel Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory. | 0.4% | — |
| CVE-2026-9973 | HIGH 8.8 | google chrome Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-6052 | MED 6.5 | ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. | 0.4% | — |
| CVE-2026-45490 | HIGH 7.8 | microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20150 | HIGH 8.8 | cisco roomos As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally d | 0.4% | — |
| CVE-2025-67604 | MED 5.3 | fortinet fortianalyzer A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7 | 0.4% | — |
| CVE-2025-59255 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59207 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-58728 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55677 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55339 | HIGH 7.8 | microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55317 | HIGH 7.8 | microsoft autoupdate Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55245 | HIGH 7.8 | microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-54115 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50175 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50152 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-0440 | MED 6.5 | google chrome Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2025-0130 | HIGH 7.5 | paloaltonetworks pan-os A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate | 0.4% | — |
| CVE-2024-49526 | HIGH 7.8 | adobe animate Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic | 0.4% | — |
| CVE-2024-41761 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query. | 0.4% | — |
| CVE-2024-39518 | HIGH 7.5 | juniper junos A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS). Wh | 0.4% | — |
| CVE-2023-47078 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0.4% | — |
| CVE-2023-47061 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0.4% | — |
| CVE-2022-34865 | MED 4.8 | f5 big-ip_access_policy_manager In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reac | 0.4% | — |
| CVE-2022-22008 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.4% | — |