58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-5546 | HIGH 7.8 | f5 big-ip_access_policy_manager The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local un | 0.5% | — |
| CVE-2018-0224 | MED 6.7 | cisco staros A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system. The vulnerab | 0.5% | — |
| CVE-2017-9497 | MED 6.8 | cisco mx011anm_firmware The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector | 0.5% | — |
| CVE-2011-4097 | MED 5.5 | linux linux_kernel Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory. | 0.5% | — |
| CVE-2009-1262 | HIGH 7.2 | fortinet forticlient Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name. | 0.5% | — |
| CVE-2026-80097 | HIGH 8.6 | microsoft authenticator Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-65613 | MED 4.3 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Use | 0.5% | — |
| CVE-2026-14973 | CRIT 9.3 | ibm aspera IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | 0.5% | — |
| CVE-2025-64679 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-27478 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-21340 | MED 5.5 | microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2025-21091 | HIGH 7.5 | f5 big-ip_access_policy_manager When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-57932 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gve: guard XDP xmit NDO on existence of xdp queues In GVE, dedicated XDP queues only exist when an XDP program is installed and the interface is up. As such, the NDO XDP XMIT callback should | 0.5% | — |
| CVE-2024-20513 | MED 5.8 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected devi | 0.5% | — |
| CVE-2023-41718 | HIGH 7.8 | ivanti secure_access_client When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. | 0.5% | — |
| CVE-2023-3772 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel c | 0.5% | — |
| CVE-2023-33855 | LOW 3.7 | ibm common_cryptographic_architecture Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM | 0.5% | — |
| CVE-2023-20134 | MED 5.4 | cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, | 0.5% | — |
| CVE-2021-3047 | MED 4.2 | paloaltonetworks pan-os A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long dur | 0.5% | — |
| CVE-2021-1052 | HIGH 7.8 | nvidia gpu_driver NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service | 0.5% | — |
| CVE-2021-0214 | MED 6.5 | juniper junos A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS may cause receipt of a malformed packet to crash and restart the PPMD process, leading to network destabilization, service interruption, and | 0.5% | — |
| CVE-2020-5900 | HIGH 8.8 | f5 nginx_controller In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface. | 0.5% | — |
| CVE-2019-19066 | MED 4.7 | canonical ubuntu_linux A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd. | 0.5% | — |
| CVE-2019-15971 | MED 4.3 | cisco email_security_appliance_firmware A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation o | 0.5% | — |
| CVE-2018-6983 | HIGH 8.8 | vmware fusion VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer overflow vulnerability in the virtual network devices. This issue may allow a guest to execute code on the host. | 0.5% | — |