IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-0546 HIGH 7.8 intel optane_dc_persistent_memory_module_management Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access. 0.3%
CVE-2019-1813 MED 6.7 cisco nx-os A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because 0.3%
CVE-2019-1812 MED 6.7 cisco nx-os A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because 0.3%
CVE-2018-0012 HIGH 7.8 juniper junos_space Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain root privileges. 0.3%
CVE-2017-1434 MED 4.7 ibm db2 IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user. 0.3%
CVE-2016-2547 MED 5.1 linux linux_kernel sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call. 0.3%
CVE-2016-2546 MED 5.1 linux linux_kernel sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call. 0.3%
CVE-2016-2544 MED 5.1 linux linux_kernel Race condition in the queue_delete function in sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local users to cause a denial of service (use-after-free and system crash) by making an ioctl call at a certain time. 0.3%
CVE-2016-0774 MED 6.8 google android The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not proper 0.3%
CVE-2014-8013 MED 4.9 cisco nx-os The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device reload) via a long CLI command, aka Bug ID CSCur54182. 0.3%
CVE-2009-5007 LOW 3.3 cisco anyconnect_ssl_vpn The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files. 0.3%
CVE-2008-1810 MED 4.4 sap maxdb Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable. 0.3%
CVE-2006-3634 MED 4.9 linux linux_kernel The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic functions in Linux kernel 2.6.17-rc4 to 2.6.18-rc2 perform the atomic futex operation in the kernel address space instead of the user address space, which allows local users to cause a denial of s 0.3%
CVE-2005-2939 HIGH 7.2 vmware workstation Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. 0.3%
CVE-2003-1291 HIGH 7.2 vmware esx VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables. 0.3%
CVE-2026-84637 CRIT 9.8 mozilla thunderbird Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear 0.3%
CVE-2026-7987 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2026-7980 HIGH 8.8 google chrome Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2026-7928 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-58185 MED 5.9 apache traffic_server The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fi 0.3%
CVE-2026-50680 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49165 HIGH 7.1 microsoft windows_10_1607 Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-45608 MED 6.8 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-40978 HIGH 8.8 vmware spring_ai SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) 0.3%
CVE-2026-33778 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service ( 0.3%