IT
57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.020 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-48821 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: avoid double fput() on failed usercopy If the copy back to userland fails for the FASTRPC_IOCTL_ALLOC_DMA_BUFF ioctl(), we shouldn't assume that 'buf->dmabuf' is still valid. 0.3%
CVE-2022-34674 MED 6.8 debian debian_linux NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak. 0.3%
CVE-2022-25294 HIGH 7.8 proofpoint insider_threat_management Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and 0.3%
CVE-2021-47600 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec(). 0.3%
CVE-2021-47145 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON in link_to_fixup_dir While doing error injection testing I got the following panic kernel BUG at fs/btrfs/tree-log.c:1862! invalid opcode: 0000 [#1] SMP NOPTI CPU 0.3%
CVE-2021-3764 MED 5.5 linux linux_kernel A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availabili 0.3%
CVE-2021-34756 MED 6.7 cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of t 0.3%
CVE-2021-34755 MED 6.7 cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of t 0.3%
CVE-2020-4980 MED 6.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539. 0.3%
CVE-2019-7819 MED 5.5 adobe acrobat_dc Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of th 0.3%
CVE-2019-15273 MED 4.4 cisco telepresence_collaboration_endpoint Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permission enforcement. An attacker could expl 0.3%
CVE-2014-5868 MED 5.4 cisco cisco_technical_support The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 0.3%
CVE-2013-1014 MED 4.3 apple itunes Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. 0.3%
CVE-2011-1637 LOW 1.5 cisco skinny_client_control_protocol_software Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962. 0.3%
CVE-2005-3847 MED 5.5 debian debian_linux The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dum 0.3%
CVE-2026-79177 MED 6.5 google chrome Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) 0.3%
CVE-2026-53357 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returnin 0.3%
CVE-2026-43828 MED 6.5 apache shiro Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, w 0.3%
CVE-2026-41225 CRIT 9.1 f5 big-ip_access_policy_manager A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Suppo 0.3%
CVE-2026-40417 HIGH 7.8 microsoft dynamics_365_business_central Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33834 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27312 HIGH 7.8 adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o 0.3%
CVE-2026-27311 HIGH 7.8 adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o 0.3%
CVE-2026-23670 MED 5.7 microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-20168 MED 6.5 cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficie 0.3%