57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1320 | MED 6.7 | cisco prime_collaboration The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286. | 0.4% | — |
| CVE-2015-0717 | MED 6.9 | cisco unified_communications_manager Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546. | 0.4% | — |
| CVE-2014-0676 | MED 6.8 | cisco nx-os Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. | 0.4% | — |
| CVE-2011-1833 | LOW 3.3 | linux linux_kernel Race condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the eCryptfs subsystem in the Linux kernel before 3.1 allows local users to bypass intended file permissions via a mount.ecryptfs_private mount with a mismatched uid. | 0.4% | — |
| CVE-2009-4664 | LOW 3.3 | fwbuilder firewall_builder Firewall Builder 3.0.4, 3.0.5, and 3.0.6, when running on Linux, allows local users to gain privileges via a symlink attack on an unspecified temporary file that is created by the iptables script. | 0.4% | — |
| CVE-2008-5716 | HIGH 7.2 | citrix xen xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) cons | 0.4% | — |
| CVE-2004-1237 | LOW 2.1 | linux linux_kernel Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors. | 0.4% | — |
| CVE-1999-1126 | LOW 2.1 | cisco resource_manager Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug. | 0.4% | — |
| CVE-2026-8854 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | 0.4% | — |
| CVE-2026-70317 | MED 5.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-64140 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in proc_show_files() When a SMB2 client opens a file with a durable v2 handle and then issues SMB2 SESSION_LOGOFF, session_fd_check() clears fp->tcon = NU | 0.4% | — |
| CVE-2026-58640 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-52960 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback The batch holds references to the folios (see `filemap_get_folios`, `folio_batch_release`), so we need to `folio_put` the folios we remove. Teste | 0.4% | — |
| CVE-2026-52956 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct | 0.4% | — |
| CVE-2026-50510 | HIGH 7.8 | microsoft github_copilot Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-50482 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-49790 | HIGH 7.3 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2026-49789 | HIGH 7.3 | microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-4676 | HIGH 8.8 | google chrome Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-39815 | HIGH 8.8 | fortinet fortiddos-f A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests | 0.4% | — |
| CVE-2026-26148 | HIGH 8.1 | microsoft azure_ad_ssh_login_extension_for_linux External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-26131 | HIGH 7.8 | microsoft .net Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-25604 | MED 5.4 | apache apache-airflow-providers-amazon In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML | 0.4% | — |
| CVE-2026-11662 | HIGH 8.8 | google chrome Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-0262 | HIGH 7.5 | paloaltonetworks pan-os Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not | 0.4% | — |