IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-58715 HIGH 8.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49694 HIGH 7.8 microsoft windows_11_24h2 Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49693 HIGH 7.8 microsoft windows_11_22h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49679 HIGH 7.8 microsoft windows_10_1507 Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-47982 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-47159 HIGH 7.8 microsoft windows_10_1507 Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2024-30058 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4% —
CVE-2024-20431 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation da 0.4% —
CVE-2024-20361 MED 5.8 cisco secure_firewall_management_center A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Fire 0.4% —
CVE-2024-20293 MED 5.8 cisco adaptive_security_appliance_software A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by 0.4% —
CVE-2024-0007 MED 6.8 paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another 0.4% —
CVE-2023-32050 HIGH 7.0 microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability 0.4% —
CVE-2023-25603 MED 5.4 fortinet fortiadc A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted 0.4% —
CVE-2022-41738 HIGH 7.5 ibm spectrum_scale_container_native_storage_access IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. 0.4% —
CVE-2022-34242 HIGH 7.8 adobe character_animator Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage 0.4% —
CVE-2022-28388 MED 5.5 debian debian_linux usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. 0.4% —
CVE-2021-38160 HIGH 7.8 debian debian_linux In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vul 0.4% —
CVE-2021-1237 HIGH 7.8 cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker w 0.4% —
CVE-2020-3972 LOW 3.3 vmware tools VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest File System (HGFS) implementation. Successful exploitation of this issue may allow attackers with non-admin privileges on guest macOS virtual m 0.4% —
CVE-2020-36163 CRIT 9.3 veritas netbackup An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, 0.4% —
CVE-2020-18171 HIGH 8.8 techsmith snagit TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. 0.4% —
CVE-2019-0070 HIGH 8.8 juniper junos An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This l 0.4% —
CVE-2018-6969 HIGH 7.0 vmware tools VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able 0.4% —
CVE-2018-17977 MED 4.4 linux linux_kernel The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute cra 0.4% —
CVE-2017-8071 MED 5.5 linux linux_kernel drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is possible in a USB HID request callback, which allows local users to cause a denial of service (deadlock) via unspecified vectors. 0.4% —