58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58732 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-54947 | CRIT 9.8 | apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf | 0.5% | — |
| CVE-2025-37935 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM If the mtk_poll_rx() function detects the MTK_RESETTING flag, it will jump to release_desc and refill the high word of the SDP on the | 0.5% | — |
| CVE-2025-34196 | CRIT 9.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in p | 0.5% | — |
| CVE-2025-32718 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-32716 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-45030 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well with large MAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload corruption on TX. An easy | 0.5% | — |
| CVE-2024-43492 | HIGH 7.8 | microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-41766 | HIGH 7.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression. | 0.5% | — |
| CVE-2024-36947 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() drops the pinning references to all positives in subtree. For the cases when its argument has been kept alive by the pinning alone that's e | 0.5% | — |
| CVE-2024-36945 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable resolved by ip_route_output_flow() are not released or | 0.5% | — |
| CVE-2024-30409 | MED 5.3 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to c | 0.5% | — |
| CVE-2024-21610 | MED 4.3 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). In a scaled CoS sce | 0.5% | — |
| CVE-2023-53335 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() If get_ep_from_tid() fails to lookup non-NULL value for ep, ep is dereferenced later regardless of whether it is empty. This patc | 0.5% | — |
| CVE-2023-46713 | MED 5.3 | fortinet fortiweb An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application. | 0.5% | — |
| CVE-2023-38110 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit th | 0.5% | — |
| CVE-2023-38109 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulner | 0.5% | — |
| CVE-2023-35363 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-38428 | MED 5.5 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitat | 0.5% | — |
| CVE-2022-26122 | MED 4.7 | fortinet antivirus_engine An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment wi | 0.5% | — |
| CVE-2022-22462 | LOW 3.7 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225078. | 0.5% | — |
| CVE-2018-1000200 | MED 5.5 | linux linux_kernel The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls munlock_vma | 0.5% | — |
| CVE-2011-4324 | MED 4.9 | linux linux_kernel The encode_share_access function in fs/nfs/nfs4xdr.c in the Linux kernel before 2.6.29 allows local users to cause a denial of service (BUG and system crash) by using the mknod system call with a pathname on an NFSv4 filesystem. | 0.5% | — |
| CVE-2011-1160 | LOW 2.1 | linux linux_kernel The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors. | 0.5% | — |
| CVE-2007-5966 | HIGH 7.2 | linux linux_kernel Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code or cause a denial of service (panic) via a large relative timeout value. NOTE: some of these details are obtai | 0.5% | — |