58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3173 | HIGH 7.8 | cisco ucs_manager A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insuffi | 0.4% | — |
| CVE-2020-25656 | MED 4.1 | debian debian_linux A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is | 0.4% | — |
| CVE-2015-4279 | HIGH 7.2 | cisco unified_computing_system The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778. | 0.4% | — |
| CVE-2015-0274 | HIGH 7.2 | linux linux_kernel The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leverag | 0.4% | — |
| CVE-2013-2897 | MED 4.7 | linux linux_kernel Multiple array index errors in drivers/hid/hid-multitouch.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_MULTITOUCH is enabled, allow physically proximate attackers to cause a denial of service (heap memory co | 0.4% | — |
| CVE-2012-3495 | MED 6.1 | citrix xenserver The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS | 0.4% | — |
| CVE-2009-1895 | HIGH 7.2 | canonical ubuntu_linux The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage th | 0.4% | — |
| CVE-2008-3539 | LOW 2.1 | hp hpsi_acf2_connector Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 a | 0.4% | — |
| CVE-2007-6434 | LOW 2.1 | linux linux_kernel Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function. | 0.4% | — |
| CVE-2026-78451 | MED 6.8 | microsoft windows_10_1809 Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-77892 | MED 6.8 | microsoft windows_10_1607 No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-72999 | MED 6.8 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-69490 | MED 6.8 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-62917 | MED 4.6 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-54132 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-52924 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, | 0.4% | — |
| CVE-2026-50668 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-50492 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50299 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50298 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-49168 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-45458 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45456 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-42904 | CRIT 9.6 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2026-21508 | HIGH 7.0 | microsoft windows_10_1607 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.4% | — |