57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3655 | LOW 3.3 | debian debian_linux A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory. | 0.3% | — |
| CVE-2021-1441 | MED 6.7 | cisco ios_xe A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Series Industrial Integrated Services Routers and Cisco ESR6300 Embedded Series Routers could allow an authenticated, local attacker to execute unsigned code at sys | 0.3% | — |
| CVE-2020-25284 | MED 4.1 | debian debian_linux The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe. | 0.3% | — |
| CVE-2020-12364 | MED 5.5 | intel graphics_drivers Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access. | 0.3% | — |
| CVE-2020-12363 | MED 5.5 | intel graphics_drivers Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access. | 0.3% | — |
| CVE-2019-6679 | LOW 3.3 | f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlink | 0.3% | — |
| CVE-2017-7889 | HIGH 7.8 | canonical ubuntu_linux The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions | 0.3% | — |
| CVE-2010-5181 | HIGH 7.0 | gfi vipre_antivirus Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain u | 0.3% | — |
| CVE-2006-5393 | MED 5.5 | cisco secure_desktop Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session. | 0.3% | — |
| CVE-1999-0401 | LOW 3.7 | linux linux_kernel A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. | 0.3% | — |
| CVE-2026-7898 | HIGH 8.8 | google chrome Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-50222 | HIGH 7.5 | apache cloudstack Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserData | 0.3% | — |
| CVE-2026-45654 | HIGH 7.9 | microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-41920 | CRIT 9.3 | apache traffic_server Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue. | 0.3% | — |
| CVE-2026-20924 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20918 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20877 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-62459 | HIGH 8.3 | microsoft 365_defender_portal Microsoft Defender Portal Spoofing Vulnerability | 0.3% | — |
| CVE-2025-54220 | HIGH 7.8 | adobe incopy InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope | 0.3% | — |
| CVE-2025-54219 | HIGH 7.8 | adobe incopy InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope | 0.3% | — |
| CVE-2025-54217 | HIGH 7.8 | adobe incopy InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope | 0.3% | — |
| CVE-2025-52960 | MED 5.9 | juniper junos A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When m | 0.3% | — |
| CVE-2025-12430 | HIGH 7.5 | google chrome Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2024-57986 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections A report in 2019 by the syzbot fuzzer was found to be connected to two errors in the HID core associated | 0.3% | — |
| CVE-2024-51954 | HIGH 8.5 | esri arcgis_server There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfedera | 0.3% | — |