58.387 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.387 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-31677 | MED 5.4 | vmware pinniped An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper | 0.4% | — |
| CVE-2022-20626 | MED 5.5 | cisco prime_access_registrar A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid creden | 0.4% | — |
| CVE-2021-3653 | HIGH 8.8 | debian debian_linux A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" | 0.4% | — |
| CVE-2021-20411 | HIGH 8.1 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191. | 0.4% | — |
| CVE-2019-19527 | MED 6.8 | debian debian_linux In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver, aka CID-9c09b214f30e. | 0.4% | — |
| CVE-2019-1829 | MED 6.7 | cisco aironet_access_point_firmware A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administrator devi | 0.4% | — |
| CVE-2018-1068 | MED 6.7 | canonical ubuntu_linux A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory. | 0.4% | — |
| CVE-2018-0294 | MED 6.7 | cisco firepower_extensible_operating_system A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected sof | 0.4% | — |
| CVE-2017-5547 | HIGH 7.8 | linux linux_kernel drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by lev | 0.4% | — |
| CVE-2013-2231 | HIGH 7.2 | redhat enterprise_linux Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Worksta | 0.4% | — |
| CVE-2011-2898 | MED 5.5 | linux linux_kernel net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a c | 0.4% | — |
| CVE-2009-0055 | MED 6.8 | cisco ironport_encryption_appliance Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before | 0.4% | — |
| CVE-2008-4445 | MED 4.7 | linux linux_kernel The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bound | 0.4% | — |
| CVE-2006-1056 | LOW 2.1 | freebsd freebsd The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one proc | 0.4% | — |
| CVE-2005-3784 | MED 4.9 | linux linux_kernel The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges. | 0.4% | — |
| CVE-2005-3105 | LOW 2.1 | linux linux_kernel The mprotect code (mprotect.c) in Linux 2.6 on Itanium IA64 Montecito processors does not properly maintain cache coherency as required by the architecture, which allows local users to cause a denial of service and possibly corrupt data by modifying PTE protec | 0.4% | — |
| CVE-2005-0210 | MED 4.9 | linux linux_kernel Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice. | 0.4% | — |
| CVE-2026-68797 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-4677 | HIGH 8.8 | google chrome Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-34487 | HIGH 7.5 | apache tomcat Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1 | 0.4% | — |
| CVE-2026-0309 | ND | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS C | 0.4% | — |
| CVE-2025-54091 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53726 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53724 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53152 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. | 0.4% | — |