57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.020 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-48821 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: avoid double fput() on failed usercopy If the copy back to userland fails for the FASTRPC_IOCTL_ALLOC_DMA_BUFF ioctl(), we shouldn't assume that 'buf->dmabuf' is still valid. | 0.3% | — |
| CVE-2022-34674 | MED 6.8 | debian debian_linux NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak. | 0.3% | — |
| CVE-2022-25294 | HIGH 7.8 | proofpoint insider_threat_management Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and | 0.3% | — |
| CVE-2021-47600 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec(). | 0.3% | — |
| CVE-2021-47145 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON in link_to_fixup_dir While doing error injection testing I got the following panic kernel BUG at fs/btrfs/tree-log.c:1862! invalid opcode: 0000 [#1] SMP NOPTI CPU | 0.3% | — |
| CVE-2021-3764 | MED 5.5 | linux linux_kernel A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availabili | 0.3% | — |
| CVE-2021-34756 | MED 6.7 | cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of t | 0.3% | — |
| CVE-2021-34755 | MED 6.7 | cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of t | 0.3% | — |
| CVE-2020-4980 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539. | 0.3% | — |
| CVE-2019-7819 | MED 5.5 | adobe acrobat_dc Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of th | 0.3% | — |
| CVE-2019-15273 | MED 4.4 | cisco telepresence_collaboration_endpoint Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permission enforcement. An attacker could expl | 0.3% | — |
| CVE-2014-5868 | MED 5.4 | cisco cisco_technical_support The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0.3% | — |
| CVE-2013-1014 | MED 4.3 | apple itunes Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | 0.3% | — |
| CVE-2011-1637 | LOW 1.5 | cisco skinny_client_control_protocol_software Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962. | 0.3% | — |
| CVE-2005-3847 | MED 5.5 | debian debian_linux The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dum | 0.3% | — |
| CVE-2026-79177 | MED 6.5 | google chrome Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-53357 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returnin | 0.3% | — |
| CVE-2026-43828 | MED 6.5 | apache shiro Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, w | 0.3% | — |
| CVE-2026-41225 | CRIT 9.1 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Suppo | 0.3% | — |
| CVE-2026-40417 | HIGH 7.8 | microsoft dynamics_365_business_central Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-33834 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27312 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.3% | — |
| CVE-2026-27311 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.3% | — |
| CVE-2026-23670 | MED 5.7 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-20168 | MED 6.5 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficie | 0.3% | — |