IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-3417 MED 6.8 cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) va 0.4% —
CVE-2019-1732 MED 6.4 cisco nx-os A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which 0.4% —
CVE-2019-1731 MED 4.4 cisco nx-os A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an authenticated, local attacker to expose a user's private SSH key to all authenticated users on the targeted device. The attacker must authenticate with valid adm 0.4% —
CVE-2018-9334 MED 5.5 paloaltonetworks pan-os The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup. 0.4% —
CVE-2017-15129 MED 4.7 canonical ubuntu_linux A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids id 0.4% —
CVE-2017-12286 MED 5.5 cisco jabber A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lac 0.4% —
CVE-2017-12284 MED 5.5 cisco jabber A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of inp 0.4% —
CVE-2016-4568 HIGH 7.8 linux linux_kernel drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call. 0.4% —
CVE-2016-2557 HIGH 8.4 nvidia gpu_driver_r340 The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information from kernel memory, cause a denial of service (crash), or possibly ga 0.4% —
CVE-2016-0287 HIGH 7.8 ibm i_access IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors. 0.4% —
CVE-2013-6024 MED 4.4 f5 big-ip_access_policy_manager The Edge Client components in F5 BIG-IP APM 10.x, 11.x, 12.x, 13.x, and 14.x, BIG-IP Edge Gateway 10.x and 11.x, and FirePass 7.0.0 allow attackers to obtain sensitive information from process memory via unspecified vectors. 0.4% —
CVE-2013-3434 MED 6.8 cisco unified_communications_manager Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui0 0.4% —
CVE-2013-0313 MED 6.2 linux linux_kernel The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or pos 0.4% —
CVE-2012-2384 MED 4.9 linux linux_kernel Integer overflow in the i915_gem_do_execbuffer function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-b 0.4% —
CVE-2012-1313 MED 6.5 cisco unified_computing_system The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macstats parameters, aka Bug ID CSCub13772. 0.4% —
CVE-2007-1271 MED 6.6 vmware esx Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors. 0.4% —
CVE-2006-0482 LOW 2.1 linux linux_kernel Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call. 0.4% —
CVE-2005-1041 LOW 2.1 linux linux_kernel The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route. 0.4% —
CVE-2005-0977 LOW 2.1 linux linux_kernel The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address. 0.4% —
CVE-2002-1554 MED 4.6 cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup. 0.4% —
CVE-2000-0267 MED 4.6 cisco catos Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. 0.4% —
CVE-2026-85532 HIGH 7.5 apache wss4j Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum k 0.4% —
CVE-2026-58162 CRIT 10.0 apache traffic_server The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended t 0.4% —
CVE-2026-48565 HIGH 7.8 microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-41088 HIGH 7.8 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —