58.434 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.434 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-2236 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a us | 0.4% | — |
| CVE-2023-21756 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-32296 | LOW 3.3 | linux linux_kernel The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056. | 0.4% | — |
| CVE-2022-26808 | HIGH 7.0 | microsoft windows_10 Windows File Explorer Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-24959 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c. | 0.4% | — |
| CVE-2022-20953 | MED 5.5 | cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a | 0.4% | — |
| CVE-2018-1799 | MED 6.2 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429. | 0.4% | — |
| CVE-2016-10208 | MED 4.3 | linux linux_kernel The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 im | 0.4% | — |
| CVE-2014-3646 | MED 5.5 | canonical ubuntu_linux arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | 0.4% | — |
| CVE-2014-3182 | MED 6.9 | linux linux_kernel Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provid | 0.4% | — |
| CVE-2010-3067 | MED 4.9 | canonical ubuntu_linux Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call. | 0.4% | — |
| CVE-2026-57989 | HIGH 7.4 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.4% | — |
| CVE-2026-53071 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in th | 0.4% | — |
| CVE-2026-32794 | MED 4.8 | apache airflow_providers_databricks Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulat | 0.4% | — |
| CVE-2026-1861 | HIGH 8.8 | google chrome Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-46706 | HIGH 7.5 | f5 big-ip_access_policy_manager When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2025-21629 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets The blamed commit disabled hardware offoad of IPv6 packets with extension headers on devices that advertise NETIF_F_IPV6_CSUM, bas | 0.4% | — |
| CVE-2025-20163 | HIGH 8.7 | cisco nexus_dashboard A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An atta | 0.4% | — |
| CVE-2024-49049 | HIGH 7.1 | microsoft remote_ssh Visual Studio Code Remote Extension Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-20274 | MED 5.5 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generat | 0.4% | — |
| CVE-2023-39221 | MED 5.4 | intel unison_software Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0.4% | — |
| CVE-2022-3545 | MED 5.5 | debian debian_linux A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use | 0.4% | — |
| CVE-2020-3508 | HIGH 7.4 | cisco ios_xe A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to | 0.4% | — |
| CVE-2017-8066 | HIGH 7.8 | linux linux_kernel drivers/net/can/usb/gs_usb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.2 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified othe | 0.4% | — |
| CVE-2017-8061 | HIGH 7.8 | linux linux_kernel drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have | 0.4% | — |