58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26909 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix drm bridge use-after-free A recent DRM series purporting to simplify support for "transparent bridges" and handling of probe deferrals ironically exposed a | 0.3% | — |
| CVE-2024-26799 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix uninitialized pointer dmactl In the case where __lpass_get_dmactl_handle is called and the driver id dai_id is invalid the pointer dmactl is not being assigned a value, and d | 0.2% | — |
| CVE-2024-26734 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: devlink: fix possible use-after-free and memory leaks in devlink_init() The pernet operations structure for the subsystem must be registered before registering the generic netlink family. M | 0.2% | — |
| CVE-2024-26660 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN301 'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four | 0.3% | — |
| CVE-2024-26243 | HIGH 7.0 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-26242 | HIGH 7.0 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2024-26236 | HIGH 7.0 | microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-26213 | HIGH 7.0 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-21445 | HIGH 7.0 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-21439 | HIGH 7.0 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-21433 | HIGH 7.0 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 5.1% | — |
| CVE-2024-21432 | HIGH 7.0 | microsoft windows_10_1507 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-21405 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-21371 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 10.9% | — |
| CVE-2024-21355 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2024-20657 | HIGH 7.0 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-0646 | HIGH 7.0 | linux linux_kernel An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileg | 0.3% | — |
| CVE-2023-6546 | HIGH 7.0 | fedoraproject fedora A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem o | 0.7% | — |
| CVE-2023-6531 | HIGH 7.0 | linux linux_kernel A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on. | 0.2% | — |
| CVE-2023-6270 | HIGH 7.0 | debian debian_linux A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access throu | 0.4% | — |
| CVE-2023-5972 | HIGH 7.0 | fedoraproject fedora A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system. | 0.3% | — |
| CVE-2023-53638 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: octeon_ep: cancel queued works in probe error path If it fails to get the devices's MAC address, octep_probe exits while leaving the delayed work intr_poll_task queued. When the work later r | 0.1% | — |
| CVE-2023-53622 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix possible data races in gfs2_show_options() Some fields such as gt_logd_secs of the struct gfs2_tune are accessed without holding the lock gt_spin in gfs2_show_options(): val = s | 0.1% | — |
| CVE-2023-53572 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: imx: scu: use _safe list iterator to avoid a use after free This loop is freeing "clk" so it needs to use list_for_each_entry_safe(). Otherwise it dereferences a freed variable to get t | 0.1% | — |
| CVE-2023-53499 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix error unwinding of XDP initialization When initializing XDP in virtnet_open(), some rq xdp initialization may hit an error causing net device open failed. However, previous r | 0.2% | — |