IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-27129 MED 6.7 cisco sd-wan_vmanage A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges. The vulnerability is due to improper validation of commands to 0.3%
CVE-2020-15852 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of 0.3%
CVE-2019-3652 MED 5.0 mcafee endpoint_security Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the 0.3%
CVE-2019-3622 HIGH 8.2 mcafee data_loss_prevention_endpoint Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder a 0.3%
CVE-2018-10074 MED 5.5 linux linux_kernel The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows local users to cause a denial of service (NULL pointer dereference) by triggering a failure of resource retrieval. 0.3%
CVE-2017-12332 MED 4.4 cisco nx-os A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could ex 0.3%
CVE-2016-8824 HIGH 7.8 nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, l 0.3%
CVE-2016-8821 HIGH 7.8 nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where improper access controls may allow a user to access arbitrary physical memory, leading to an escalation of privileges. 0.3%
CVE-2015-0755 MED 6.8 cisco anyconnect_secure_mobility_client The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797. 0.3%
CVE-2010-5313 MED 4.9 linux linux_kernel Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842. 0.3%
CVE-2007-6209 MED 4.6 zsh zsh Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files. 0.3%
CVE-2005-3527 MED 4.0 linux linux_kernel Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP. 0.3%
CVE-2026-7361 HIGH 8.8 google chrome Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-59085 CRIT 9.1 apache cloudstack Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended 0.3%
CVE-2026-42916 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42837 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42828 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34343 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25972 MED 4.3 fortinet fortisiem An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering 0.3%
CVE-2026-24033 HIGH 7.2 apache traffic_server Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to vers 0.3%
CVE-2026-20844 HIGH 7.4 microsoft windows_10_1607 Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-10906 HIGH 7.5 google chrome Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2025-8011 HIGH 8.8 google chrome Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2025-8010 HIGH 8.8 google chrome Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2025-20205 MED 4.8 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerab 0.3%