IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-61923 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61357 HIGH 7.8 microsoft windows_11_24h2 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61355 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61353 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59127 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-53178 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer un 0.3%
CVE-2026-50310 MED 4.7 microsoft windows_10_1809 Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-33119 MED 5.4 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2026-31607 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets fr 0.3%
CVE-2026-21914 HIGH 7.5 juniper junos An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). If an SRX Series device receives a specifically malformed GPRS Tunnelling Prot 0.3%
CVE-2026-20958 MED 5.4 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0.3%
CVE-2025-62224 MED 5.5 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2025-38209 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvm 0.3%
CVE-2023-24920 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.3%
CVE-2020-1984 HIGH 7.8 paloaltonetworks secdo Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. Th 0.3%
CVE-2020-10781 MED 5.5 debian debian_linux A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel me 0.3%
CVE-2018-6265 HIGH 7.8 nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who initiates a browser session may obtain escalation of privileges on the browser. 0.3%
CVE-2018-6263 HIGH 7.8 nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has access to a local user account can plant a malicious dynamic link library (DLL) during application installation, which may lead to escalati 0.3%
CVE-2017-6256 HIGH 7.8 nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of 0.3%
CVE-2017-12550 MED 5.6 hp system_management_homepage A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. 0.3%
CVE-2017-12136 HIGH 7.8 citrix xenserver Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling. 0.3%
CVE-2016-4924 HIGH 8.4 juniper junos An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host system read access to vMX or vPFE images and obtain sensitive information contained in them such as private cryptographic keys. This issue w 0.3%
CVE-2013-5493 MED 6.8 cisco virtualization_experience_client_6000 The diagnostic module in the firmware on Cisco Virtualization Experience Client 6000 devices allows local users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors, aka Bug ID CSCug68407. 0.3%
CVE-2007-3720 LOW 2.1 linux linux_kernel The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result 0.3%
CVE-1999-0782 LOW 2.1 freebsd freebsd KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. 0.3%