58.515 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.515 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1437 | HIGH 7.0 | debian debian_linux Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl | 0.7% | — |
| CVE-2009-3547 | HIGH 7.0 | canonical ubuntu_linux Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname. | 4.9% | — |
| CVE-2009-1143 | HIGH 7.0 | vmware open-vm-tools An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter). | 0.3% | — |
| CVE-1999-0012 | HIGH 7.0 | microsoft frontpage Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | 18.5% | — |
| CVE-2026-9154 | HIGH 7.1 | gnu sed Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter. | 0.4% | — |
| CVE-2026-86089 | HIGH 7.1 | apache nifi Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connec | 0.4% | — |
| CVE-2026-80685 | HIGH 7.1 | In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in snapshot_page() snapshot_page() currently reads __page_2 after checking nr_pages > 1, but it should only do so when nr_pages > 2. If an or | 0.2% | — |
| CVE-2026-80530 | HIGH 7.1 | In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file tha | 0.2% | — |
| CVE-2026-8036 | HIGH 7.1 | ni ni-pal Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux. | 0.2% | — |
| CVE-2026-8035 | HIGH 7.1 | ni ni-pal Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux. | 0.1% | — |
| CVE-2026-78892 | HIGH 7.1 | google chrome Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2026-69775 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69761 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69757 | HIGH 7.1 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69706 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69688 | HIGH 7.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69602 | HIGH 7.1 | microsoft windows_10_1809 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69597 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69553 | HIGH 7.1 | microsoft windows_10_1809 Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69536 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69482 | HIGH 7.1 | microsoft windows_10_1607 Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-69460 | HIGH 7.1 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69451 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69396 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69384 | HIGH 7.1 | microsoft windows_10_1607 Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally. | 0.4% | — |