IT
57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.075 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-38179 HIGH 8.8 microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability 0.4%
CVE-2024-34117 HIGH 7.8 adobe photoshop Photoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op 0.4%
CVE-2024-3386 MED 5.3 paloaltonetworks pan-os An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to 0.4%
CVE-2023-36568 HIGH 7.0 microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 0.4%
CVE-2023-35337 HIGH 7.8 microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability 0.4%
CVE-2023-26020 MED 5.7 craftercms crafter_cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1. 0.4%
CVE-2023-23381 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.4%
CVE-2022-49743 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ovl: Use "buf" flexible array for memcpy() destination The "buf" flexible array needs to be the memcpy() destination to avoid false positive run-time warning from the recent FORTIFY_SOURCE h 0.4%
CVE-2022-35642 MED 5.4 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus 0.4%
CVE-2021-40683 HIGH 7.8 akamai enterprise_application_access In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution. 0.4%
CVE-2021-20226 HIGH 7.8 linux linux_kernel A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing ope 0.4%
CVE-2019-17650 HIGH 7.8 fortinet forticlient An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security ch 0.4%
CVE-2019-16234 MED 4.7 canonical ubuntu_linux drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. 0.4%
CVE-2019-14898 HIGH 7.0 linux linux_kernel The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with m 0.4%
CVE-2018-0428 MED 6.7 cisco web_security_appliance A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due 0.4%
CVE-2017-4934 HIGH 8.8 vmware fusion VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host. 0.4%
CVE-2017-17449 MED 4.7 linux linux_kernel The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON is enabled, does not restrict observations of Netlink messages to a single net namespace, which allows local users to obtain sensitive info 0.4%
CVE-2017-13695 MED 5.5 linux linux_kernel The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR 0.4%
CVE-2017-10663 HIGH 7.8 linux linux_kernel The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors. 0.4%
CVE-2017-10603 HIGH 7.0 juniper junos An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos 0.4%
CVE-2015-6385 HIGH 7.2 cisco ios The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, 0.4%
CVE-2015-5706 MED 4.6 canonical ubuntu_linux Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a du 0.4%
CVE-2015-4185 MED 6.9 cisco ios The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202. 0.4%
CVE-2014-9419 LOW 2.1 linux linux_kernel The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the ASLR prot 0.4%
CVE-2007-2875 LOW 2.1 canonical ubuntu_linux Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpu 0.4%