57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15315 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch. | 0.4% | — |
| CVE-2018-19965 | MED 5.6 | citrix xenserver An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorr | 0.4% | — |
| CVE-2018-19962 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | 0.4% | — |
| CVE-2018-19961 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | 0.4% | — |
| CVE-2018-14678 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized | 0.4% | — |
| CVE-2017-4948 | HIGH 7.1 | vmware horizon_view VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or | 0.4% | — |
| CVE-2017-17863 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecif | 0.4% | — |
| CVE-2017-12552 | MED 5.6 | hp system_management_homepage A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | 0.4% | — |
| CVE-2016-7388 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference caused by invalid user input | 0.4% | — |
| CVE-2016-7381 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a user input to index an array is not | 0.4% | — |
| CVE-2014-3645 | LOW 2.1 | linux linux_kernel arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | 0.4% | — |
| CVE-2011-1477 | HIGH 7.2 | linux linux_kernel Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer. | 0.4% | — |
| CVE-2006-5755 | MED 4.9 | linux linux_kernel Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the | 0.4% | — |
| CVE-2026-54999 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. | 0.4% | — |
| CVE-2026-43826 | MED 6.5 | apache apache-airflow-providers-opensearch The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read | 0.4% | — |
| CVE-2026-41018 | MED 6.5 | apache apache-airflow-providers-elasticsearch The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log r | 0.4% | — |
| CVE-2026-34477 | MED 5.9 | apache log4j The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2 | 0.4% | — |
| CVE-2026-28814 | HIGH 7.5 | apache jspwiki Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. | 0.4% | — |
| CVE-2026-22068 | HIGH 8.2 | apache traffic_server Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. | 0.4% | — |
| CVE-2025-59790 | MED 5.4 | apache kvrocks Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. | 0.4% | — |
| CVE-2025-59355 | MED 6.5 | apache linkis A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive informat | 0.4% | — |
| CVE-2025-54103 | HIGH 7.4 | microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-25539 | MED 6.5 | onespan vasco_self-service_portal Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu. | 0.4% | — |
| CVE-2025-1915 | HIGH 8.1 | google chrome Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extensi | 0.4% | — |
| CVE-2024-9468 | HIGH 7.5 | paloaltonetworks pan-os A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condi | 0.4% | — |