IT
58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2015-0717 MED 6.9 cisco unified_communications_manager Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546. 0.4% —
CVE-2014-0676 MED 6.8 cisco nx-os Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. 0.4% —
CVE-2011-1833 LOW 3.3 linux linux_kernel Race condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the eCryptfs subsystem in the Linux kernel before 3.1 allows local users to bypass intended file permissions via a mount.ecryptfs_private mount with a mismatched uid. 0.4% —
CVE-2008-5716 HIGH 7.2 citrix xen xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) cons 0.4% —
CVE-2006-5808 MED 4.6 cisco secure_desktop The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privil 0.4% —
CVE-2004-1237 LOW 2.1 linux linux_kernel Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors. 0.4% —
CVE-1999-1126 LOW 2.1 cisco resource_manager Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug. 0.4% —
CVE-2026-4463 HIGH 8.8 google chrome Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-4448 HIGH 8.8 google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-4444 HIGH 8.8 google chrome Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-4442 HIGH 8.8 google chrome Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-40948 MED 5.4 apache apache-airflow-providers-keycloak The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could delive 0.4% —
CVE-2026-3544 HIGH 8.8 google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-21743 HIGH 7.2 fortinet fortiauthenticator A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local use 0.4% —
CVE-2026-20286 MED 4.3 A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side vali 0.4% —
CVE-2026-20285 MED 4.3 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This v 0.4% —
CVE-2025-55230 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53789 HIGH 7.8 microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53782 HIGH 8.4 microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53721 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53140 HIGH 7.0 microsoft windows_10_1507 Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53133 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-50167 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-39770 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel inco 0.4% —
CVE-2025-3940 MED 5.3 tridium niagara Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15. 0.4% —