IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-16648 MED 6.6 linux linux_kernel The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device. NO 0.4% —
CVE-2017-16533 MED 6.6 canonical ubuntu_linux The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device. 0.4% —
CVE-2016-9083 HIGH 7.8 linux linux_kernel drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file for a VFIO_D 0.4% —
CVE-2015-6424 HIGH 7.2 cisco application_policy_infrastructure_controller The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985. 0.4% —
CVE-2015-6383 HIGH 7.2 cisco ios_xe Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130. 0.4% —
CVE-2015-6322 MED 6.6 cisco anyconnect_secure_mobility_client The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move arbitrary files by leveraging the lack of source-path validation, aka Bug ID CSCuv48563. 0.4% —
CVE-2013-2895 MED 5.4 linux linux_kernel drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obta 0.4% —
CVE-2013-1956 LOW 2.1 linux linux_kernel The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions via a c 0.4% —
CVE-2009-3556 LOW 1.9 linux linux_kernel A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete fi 0.4% —
CVE-2005-0839 HIGH 7.2 linux linux_kernel Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions. 0.4% —
CVE-2005-0489 MED 4.9 linux linux_kernel The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory. 0.4% —
CVE-2002-1105 MED 4.6 cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password. 0.4% —
CVE-2002-0429 LOW 3.6 linux linux_kernel The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall). 0.4% —
CVE-2001-1390 MED 6.2 linux linux_kernel Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages. 0.4% —
CVE-1999-1352 MED 4.6 linux linux_kernel mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges. 0.4% —
CVE-2026-9957 HIGH 8.8 google chrome Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) 0.4% —
CVE-2026-9186 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.). 0.4% —
CVE-2026-87585 HIGH 8.8 google chrome Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) 0.4% —
CVE-2026-76434 MED 4.9 cisco identity_services_engine A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the atta 0.4% —
CVE-2026-59119 HIGH 7.3 microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-53395 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dead ACL conflict guard in nfsd4_create nfsd4_create() steals create->cr_dpacl/cr_pacl into the local nfsd_attrs via the designated initializer, then immediately sets the source po 0.4% —
CVE-2024-40706 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system. 0.4% —
CVE-2024-21337 MED 5.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.4% —
CVE-2024-0011 MED 4.3 paloaltonetworks pan-os A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a maliciou 0.4% —
CVE-2023-47056 HIGH 7.8 adobe premiere_pro Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti 0.4% —