58.515 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.515 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-43056 | MED 5.5 | fedoraproject fedora An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 regi | 0.4% | — |
| CVE-2021-41334 | HIGH 7.0 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2019-4654 | MED 4.8 | ibm qradar_security_information_and_event_manager IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-ForceID: 170965. | 0.4% | — |
| CVE-2019-1725 | MED 5.5 | cisco unified_computing_system A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker could inject CLI comm | 0.4% | — |
| CVE-2017-9059 | MED 5.5 | linux linux_kernel The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an NFSv4 filesystem, aka a "module reference and kernel daemon" | 0.4% | — |
| CVE-2016-1339 | HIGH 7.8 | cisco unified_computing_system_platform_emulator Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832. | 0.4% | — |
| CVE-2015-3002 | MED 6.9 | juniper junos Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stan | 0.4% | — |
| CVE-2014-6195 | LOW 1.9 | ibm tivoli_storage_manager The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Wind | 0.4% | — |
| CVE-2014-5206 | HIGH 7.2 | canonical ubuntu_linux The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protectio | 0.4% | — |
| CVE-2014-3312 | MED 6.9 | cisco spa901_1-line_ip_phone The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to th | 0.4% | — |
| CVE-2013-2128 | MED 5.5 | linux linux_kernel The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket. | 0.4% | — |
| CVE-2011-0716 | MED 4.7 | linux linux_kernel The br_multicast_add_group function in net/bridge/br_multicast.c in the Linux kernel before 2.6.38, when a certain Ethernet bridge configuration is used, allows local users to cause a denial of service (memory corruption and system crash) by sending IGMP packe | 0.4% | — |
| CVE-2010-4296 | HIGH 7.2 | vmware fusion vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows ho | 0.4% | — |
| CVE-2009-4215 | HIGH 7.2 | pandasecurity panda_antivirus Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs. | 0.4% | — |
| CVE-2007-1876 | HIGH 7.2 | vmware workstation VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction." | 0.4% | — |
| CVE-2006-5823 | MED 4.0 | linux linux_kernel The zlib_inflate function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via a malformed filesystem that uses zlib compression that triggers memory corruption, as demonstrated using cramfs. | 0.4% | — |
| CVE-2006-2679 | HIGH 7.2 | cisco vpn_client Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain privileges, p | 0.4% | — |
| CVE-2005-0822 | LOW 2.1 | citrix metaframe_password_manager Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | 0.4% | — |
| CVE-1999-0171 | LOW 2.1 | linux linux_kernel Denial of service in syslog by sending it a large number of superfluous messages. | 0.4% | — |
| CVE-2026-86466 | HIGH 8.1 | apache apache-airflow-providers-fab Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client applic | 0.4% | — |
| CVE-2026-59287 | MED 5.9 | vmware spring_for_graphql Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9 | 0.4% | — |
| CVE-2026-41840 | MED 5.9 | vmware spring_framework Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. | 0.4% | — |
| CVE-2026-33799 | MED 4.3 | juniper junos An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of th | 0.4% | — |
| CVE-2026-20281 | HIGH 7.5 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS | 0.4% | — |
| CVE-2025-6724 | HIGH 8.8 | chef automate In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command. | 0.4% | — |