58.483 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.483 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15315 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch. | 0.4% | — |
| CVE-2018-19965 | MED 5.6 | citrix xenserver An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorr | 0.4% | — |
| CVE-2018-19962 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | 0.4% | — |
| CVE-2018-19961 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | 0.4% | — |
| CVE-2018-14678 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized | 0.4% | — |
| CVE-2017-4948 | HIGH 7.1 | vmware horizon_view VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or | 0.4% | — |
| CVE-2017-17863 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecif | 0.4% | — |
| CVE-2017-16644 | MED 6.6 | linux linux_kernel The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (improper error handling and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.4% | — |
| CVE-2017-16537 | MED 6.6 | linux linux_kernel The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.4% | — |
| CVE-2017-12552 | MED 5.6 | hp system_management_homepage A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | 0.4% | — |
| CVE-2016-7388 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference caused by invalid user input | 0.4% | — |
| CVE-2016-7381 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a user input to index an array is not | 0.4% | — |
| CVE-2014-3645 | LOW 2.1 | linux linux_kernel arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | 0.4% | — |
| CVE-2011-1477 | HIGH 7.2 | linux linux_kernel Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer. | 0.4% | — |
| CVE-2006-5755 | MED 4.9 | linux linux_kernel Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the | 0.4% | — |
| CVE-2026-64095 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid double decrement of bla.num_requests The bla.num_requests is increased when no request_sent was in progress. And it is decremented in various places (announcement was | 0.4% | — |
| CVE-2026-50420 | MED 6.2 | microsoft windows_11_24h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-42924 | HIGH 8.7 | f5 big-ip_access_policy_manager An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not e | 0.4% | — |
| CVE-2026-41953 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Tech | 0.4% | — |
| CVE-2026-40698 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege esca | 0.4% | — |
| CVE-2026-40631 | HIGH 8.7 | f5 big-ip_access_policy_manager An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.4% | — |
| CVE-2026-40061 | HIGH 8.7 | f5 big-ip_domain_name_system When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with | 0.4% | — |
| CVE-2026-32673 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c | 0.4% | — |
| CVE-2026-25228 | MED 5.0 | signalk signal_k_server Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and dir | 0.4% | — |
| CVE-2026-20923 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |