IT
58.444 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.444 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-12239 MED 6.8 cisco ios_xe A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system. The 0.4% —
CVE-2016-10147 MED 5.5 linux linux_kernel crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5). 0.4% —
CVE-2015-4167 MED 4.7 canonical ubuntu_linux The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF files 0.4% —
CVE-2013-7268 MED 4.9 linux linux_kernel The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory v 0.4% —
CVE-2013-7267 MED 4.9 linux linux_kernel The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel mem 0.4% —
CVE-2013-7266 MED 4.9 linux linux_kernel The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information f 0.4% —
CVE-2013-7264 MED 4.9 linux linux_kernel The l2tp_ip_recvmsg function in net/l2tp/l2tp_ip.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel sta 0.4% —
CVE-2010-3084 HIGH 7.2 canonical ubuntu_linux Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command. 0.4% —
CVE-2010-2492 HIGH 7.8 avaya aura_communication_manager Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors. 0.4% —
CVE-2010-2226 LOW 2.1 canonical ubuntu_linux The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into anothe 0.4% —
CVE-2006-1860 LOW 2.1 linux linux_kernel lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack. 0.4% —
CVE-2006-0095 LOW 2.1 linux linux_kernel dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key. 0.4% —
CVE-2026-77491 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-73180 MED 6.8 apache tomcat Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not b 0.4% —
CVE-2026-58522 MED 6.8 microsoft edge_chromium Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-53198 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A deferred byte-range lock (an SMB2_LOCK that blocks) registers an async work on conn->async_requests via setup_async_ 0.4% —
CVE-2026-20283 MED 6.5 A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.  This vulnerability is due to insufficient validation of user-supplied input in I 0.4% —
CVE-2025-64786 LOW 3.3 adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverag 0.4% —
CVE-2025-62223 MED 4.3 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0.4% —
CVE-2025-49731 LOW 3.1 microsoft teams Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. 0.4% —
CVE-2025-29833 HIGH 7.7 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-24320 HIGH 8.0 f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CV 0.4% —
CVE-2024-52983 HIGH 7.8 adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim 0.4% —
CVE-2024-44992 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid possible NULL dereference in cifs_free_subrequest() Clang static checker (scan-build) warning: cifsglob.h:line 890, column 3 Access to field 'ops' results in a dereferenc 0.4% —
CVE-2024-41046 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. 0.4% —