IT
58.543 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.543 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2020-25704 MED 5.5 debian debian_linux A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service. 0.4% —
CVE-2020-15657 HIGH 7.8 mozilla firefox Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operat 0.4% —
CVE-2018-7480 HIGH 7.8 canonical ubuntu_linux The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure. 0.4% —
CVE-2018-0362 MED 4.3 cisco 5100_enterprise_network_compute_system_firmware A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as 0.4% —
CVE-2017-6795 MED 4.4 cisco ios_xe A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device. The 0.4% —
CVE-2013-5973 MED 4.4 vmware esx VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3 0.4% —
CVE-2010-1347 HIGH 7.2 ibm director_agent Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts. 0.4% —
CVE-2009-5008 LOW 2.1 cisco secure_desktop Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file. 0.4% —
CVE-2026-50520 HIGH 8.4 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-41713 HIGH 8.2 vmware spring_ai A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across con 0.4% —
CVE-2026-11024 HIGH 8.8 google chrome Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2025-49726 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49687 HIGH 8.8 microsoft windows_10_1507 Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-23329 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and accessing the shared memory region used by the Python backend. A successful exploit of this vulnerability might lea 0.4% —
CVE-2024-47422 HIGH 7.8 adobe framemaker Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, whi 0.4% —
CVE-2024-45138 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m 0.4% —
CVE-2024-20305 MED 4.8 cisco unity_connection A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based manage 0.4% —
CVE-2023-47050 MED 5.5 adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0.4% —
CVE-2023-47049 MED 5.5 adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0.4% —
CVE-2023-47048 MED 5.5 adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0.4% —
CVE-2023-44153 HIGH 7.5 acronis cyber_protect Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. 0.4% —
CVE-2023-43123 MED 5.5 apache storm On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Ope 0.4% —
CVE-2022-44650 HIGH 7.8 trendmicro apex_one A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ab 0.4% —
CVE-2022-44649 HIGH 7.8 trendmicro apex_one An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain th 0.4% —
CVE-2022-3636 MED 5.5 debian debian_linux A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. Such manipulation leads to use after f 0.4% —