58.515 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.515 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35788 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privileg | 0.5% | — |
| CVE-2023-22448 | MED 5.9 | intel unison_software Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access. | 0.5% | — |
| CVE-2022-42438 | HIGH 7.5 | ibm cloud_pak_for_multicloud_management_monitoring IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210. | 0.5% | — |
| CVE-2022-30187 | MED 4.7 | microsoft azure_storage_blobs Azure Storage Library Information Disclosure Vulnerability | 0.5% | — |
| CVE-2021-38982 | MED 5.4 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo | 0.5% | — |
| CVE-2021-38977 | MED 4.3 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the us | 0.5% | — |
| CVE-2018-6559 | LOW 3.3 | canonical ubuntu_linux The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace. | 0.5% | — |
| CVE-2018-1923 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859. | 0.5% | — |
| CVE-2016-9754 | HIGH 7.8 | linux linux_kernel The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_si | 0.5% | — |
| CVE-2008-3535 | MED 4.9 | canonical ubuntu_linux Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testc | 0.5% | — |
| CVE-2008-3534 | MED 4.9 | canonical ubuntu_linux The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrate | 0.5% | — |
| CVE-2006-3635 | MED 5.5 | linux linux_kernel The ia64 subsystem in the Linux kernel before 2.6.26 allows local users to cause a denial of service (stack consumption and system crash) via a crafted application that leverages the mishandling of invalid Register Stack Engine (RSE) state. | 0.5% | — |
| CVE-2026-76441 | CRIT 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.5% | — |
| CVE-2025-49745 | MED 5.4 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-29829 | MED 5.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-24404 | HIGH 8.8 | apache hertzbeat XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerabili | 0.5% | — |
| CVE-2025-24072 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24059 | HIGH 7.8 | microsoft windows_10_1507 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24050 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24048 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24046 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-21183 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2025-21182 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-40999 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors consistency Validate that `first` flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a r | 0.5% | — |
| CVE-2024-26692 | HIGH 8.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an | 0.5% | — |