IT
58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-48985 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix race on per-CQ variable napi work_done After calling napi_complete_done(), the NAPIF_STATE_SCHED bit may be cleared, and another CPU can start napi thread and access per-CQ va 0.6%
CVE-2022-39959 HIGH 7.8 panini everest_engine Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\ 0.6%
CVE-2022-39842 MED 6.1 debian debian_linux An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is 0.6%
CVE-2022-22746 MED 5.9 mozilla firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Fi 0.6%
CVE-2021-27064 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability 0.6%
CVE-2020-6175 MED 5.9 citrix citrix_sd-wan_center Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. 0.6%
CVE-2016-1467 MED 6.5 cisco videoscape_session_resource_manager Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. 0.6%
CVE-2015-5652 HIGH 7.2 python python Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime 0.6%
CVE-2026-42987 HIGH 8.1 microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-54656 MED 6.5 apache struts_extras ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without an 0.6%
CVE-2023-4335 HIGH 7.5 broadcom raid_controller_web_interface Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux 0.6%
CVE-2023-36729 HIGH 7.8 microsoft windows_10_1507 Named Pipe File System Elevation of Privilege Vulnerability 0.6%
CVE-2023-20034 HIGH 7.5 cisco sd-wan Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. 0.6%
CVE-2022-38043 MED 5.5 microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability 0.6%
CVE-2022-38026 MED 5.5 microsoft windows_10 Windows DHCP Client Information Disclosure Vulnerability 0.6%
CVE-2022-38025 MED 5.5 microsoft windows_11 Windows Distributed File System (DFS) Information Disclosure Vulnerability 0.6%
CVE-2022-37996 MED 5.5 microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability 0.6%
CVE-2021-33762 HIGH 7.0 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.6%
CVE-2020-25670 HIGH 7.8 debian debian_linux A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations. 0.6%
CVE-2020-17163 HIGH 7.8 microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability 0.6%
CVE-2019-15239 HIGH 7.8 debian debian_linux In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was inte 0.6%
CVE-2019-13648 MED 5.5 linux linux_kernel In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service (TM Bad Thing exception and system crash) via a sigreturn() system call that sends a crafted signal frame. Thi 0.6%
CVE-2015-4036 HIGH 7.2 linux linux_kernel Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPO 0.6%
CVE-2014-8371 MED 4.3 vmware vcenter_server_appliance VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via 0.6%
CVE-2014-7826 HIGH 7.8 linux linux_kernel kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a c 0.6%