58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-32761 | MED 6.5 | f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of | 0.5% | — |
| CVE-2023-38106 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0.5% | — |
| CVE-2023-38105 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0.5% | — |
| CVE-2023-38046 | MED 5.5 | paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. | 0.5% | — |
| CVE-2023-28276 | MED 4.4 | microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2022-22944 | MED 5.4 | vmware workspace_one_boxer VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary scr | 0.5% | — |
| CVE-2014-9584 | LOW 2.1 | canonical ubuntu_linux The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory vi | 0.5% | — |
| CVE-2014-7975 | MED 5.5 | canonical ubuntu_linux The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writabi | 0.5% | — |
| CVE-2013-7265 | MED 4.9 | linux linux_kernel The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack | 0.5% | — |
| CVE-2013-7263 | MED 4.9 | linux linux_kernel The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvm | 0.5% | — |
| CVE-2013-0914 | LOW 3.6 | linux linux_kernel The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted applicatio | 0.5% | — |
| CVE-2010-3881 | LOW 2.1 | linux linux_kernel arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device. | 0.5% | — |
| CVE-2003-0984 | MED 4.6 | linux linux_kernel Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space. | 0.5% | — |
| CVE-2026-87621 | CRIT 9.6 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-87512 | CRIT 9.6 | google chrome Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-87494 | CRIT 9.6 | google chrome Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.5% | — |
| CVE-2026-79138 | CRIT 9.6 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-79019 | CRIT 9.6 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-78989 | CRIT 9.6 | google chrome Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-65656 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-50650 | HIGH 7.8 | microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-47292 | HIGH 7.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-41225 | CRIT 9.1 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Suppo | 0.5% | — |
| CVE-2026-39459 | HIGH 7.2 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reac | 0.5% | — |