58.553 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.553 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26828 | HIGH 7.0 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2020-3996 | MED 5.5 | vmware velero Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users. | 0.4% | — |
| CVE-2020-3234 | HIGH 8.8 | cisco ios A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, l | 0.4% | — |
| CVE-2020-14390 | MED 5.6 | debian debian_linux A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled o | 0.4% | — |
| CVE-2019-1682 | HIGH 7.8 | cisco application_policy_infrastructure_controller A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerability is due to insuffici | 0.4% | — |
| CVE-2019-12671 | HIGH 7.8 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of th | 0.4% | — |
| CVE-2018-15471 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queue | 0.4% | — |
| CVE-2017-4895 | HIGH 8.8 | vmware airwatch_agent Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data. | 0.4% | — |
| CVE-2017-12350 | HIGH 8.2 | cisco umbrella_virtual_appliance A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user crede | 0.4% | — |
| CVE-2016-8660 | MED 5.5 | linux linux_kernel The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implement | 0.4% | — |
| CVE-2015-0660 | HIGH 7.2 | cisco telepresence_server_software Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123. | 0.4% | — |
| CVE-2013-6689 | MED 6.9 | cisco unified_communications_manager Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229. | 0.4% | — |
| CVE-2012-4104 | MED 6.6 | cisco unified_computing_system Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary files via a full pathname in an image header, aka Bug ID CSCtq0 | 0.4% | — |
| CVE-2010-4649 | MED 6.9 | linux linux_kernel Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a ce | 0.4% | — |
| CVE-2001-1273 | LOW 2.1 | linux linux_kernel The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt). | 0.4% | — |
| CVE-2026-82443 | CRIT 9.6 | adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of | 0.4% | — |
| CVE-2026-49871 | CRIT 9.3 | apache apisix Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a | 0.4% | — |
| CVE-2026-47849 | HIGH 7.1 | vmware spring_data_rest Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Dat | 0.4% | — |
| CVE-2026-31629 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc | 0.4% | — |
| CVE-2026-20103 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting | 0.4% | — |
| CVE-2026-0900 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-69273 | HIGH 7.5 | broadcom dx_netops_spectrum Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | 0.4% | — |
| CVE-2025-58737 | HIGH 7.0 | microsoft windows_server_2012 Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2024-5591 | MED 4.3 | ibm jazz_foundation IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | 0.4% | — |
| CVE-2024-36032 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case | 0.4% | — |