57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-6383 | HIGH 7.2 | cisco ios_xe Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130. | 0.4% | — |
| CVE-2015-6322 | MED 6.6 | cisco anyconnect_secure_mobility_client The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move arbitrary files by leveraging the lack of source-path validation, aka Bug ID CSCuv48563. | 0.4% | — |
| CVE-2013-2895 | MED 5.4 | linux linux_kernel drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obta | 0.4% | — |
| CVE-2013-1956 | LOW 2.1 | linux linux_kernel The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions via a c | 0.4% | — |
| CVE-2009-3556 | LOW 1.9 | linux linux_kernel A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete fi | 0.4% | — |
| CVE-2005-0839 | HIGH 7.2 | linux linux_kernel Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions. | 0.4% | — |
| CVE-2005-0489 | MED 4.9 | linux linux_kernel The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory. | 0.4% | — |
| CVE-2002-1105 | MED 4.6 | cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password. | 0.4% | — |
| CVE-2002-0429 | LOW 3.6 | linux linux_kernel The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall). | 0.4% | — |
| CVE-2001-1390 | MED 6.2 | linux linux_kernel Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages. | 0.4% | — |
| CVE-1999-1352 | MED 4.6 | linux linux_kernel mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges. | 0.4% | — |
| CVE-2026-45490 | HIGH 7.8 | microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-27930 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-24255 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vuln | 0.4% | — |
| CVE-2026-23459 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats( | 0.4% | — |
| CVE-2026-14111 | HIGH 8.1 | google chrome Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low) | 0.4% | — |
| CVE-2025-27196 | HIGH 7.8 | adobe premiere_pro Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0.4% | — |
| CVE-2025-27193 | HIGH 7.8 | adobe bridge Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.4% | — |
| CVE-2025-23328 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service. | 0.4% | — |
| CVE-2024-23454 | MED 6.2 | apache hadoop Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary dir | 0.4% | — |
| CVE-2024-21405 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-33163 | HIGH 7.5 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-20871 | HIGH 7.8 | vmware fusion VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | 0.4% | — |
| CVE-2020-4668 | HIGH 8.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the | 0.4% | — |
| CVE-2020-3473 | HIGH 7.8 | cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is due to incorrect mapp | 0.4% | — |