57.084 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.084 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-25003 | HIGH 7.3 | microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24998 | HIGH 7.3 | microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24854 | MED 6.1 | apache jspwiki A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki us | 0.4% | — |
| CVE-2024-46911 | MED 4.7 | apache roller Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protectio | 0.4% | — |
| CVE-2024-43373 | HIGH 7.7 | j4k0xb webcrack webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles fea | 0.4% | — |
| CVE-2022-40140 | MED 5.5 | trendmicro apex_one An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged cod | 0.4% | — |
| CVE-2022-38425 | MED 5.5 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation | 0.4% | — |
| CVE-2021-42714 | HIGH 7.8 | splashtop splashtop Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | 0.4% | — |
| CVE-2019-5670 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access me | 0.4% | — |
| CVE-2019-1910 | HIGH 7.4 | cisco carrier_routing_system A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a den | 0.4% | — |
| CVE-2017-17543 | HIGH 7.5 | fortinet forticlient Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a | 0.4% | — |
| CVE-2017-12551 | MED 5.6 | hp system_management_homepage A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | 0.4% | — |
| CVE-2014-9683 | LOW 3.6 | canonical ubuntu_linux Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges vi | 0.4% | — |
| CVE-2013-6886 | HIGH 7.2 | realvnc realvnc RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) vncserver, (2) vncserver-x11, or (3) Xvnc helper. | 0.4% | — |
| CVE-2010-0410 | MED 4.9 | canonical ubuntu_linux drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages. | 0.4% | — |
| CVE-2006-4535 | MED 4.9 | linux linux_kernel The Linux kernel 2.6.17.10 and 2.6.17.11 and 2.6.18-rc5 allows local users to cause a denial of service (crash) via an SCTP socket with a certain SO_LINGER value, possibly related to the patch for CVE-2006-3745. NOTE: older kernel versions for specific Linux | 0.4% | — |
| CVE-2006-4145 | MED 4.9 | linux linux_kernel The Universal Disk Format (UDF) filesystem driver in Linux kernel 2.6.17 and earlier allows local users to cause a denial of service (hang and crash) via certain operations involving truncated files, as demonstrated via the dd command. | 0.4% | — |
| CVE-2026-65092 | HIGH 8.5 | nvidia openshell NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | 0.4% | — |
| CVE-2026-35440 | MED 5.5 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-25700 | HIGH 7.2 | apache answer Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactiva | 0.4% | — |
| CVE-2025-20276 | LOW 3.8 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.&nb | 0.4% | — |
| CVE-2024-49781 | HIGH 7.1 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | 0.4% | — |
| CVE-2024-37028 | MED 5.3 | f5 big-ip_next_central_manager BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2023-43018 | MED 5.9 | ibm cics_tx IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163. | 0.4% | — |
| CVE-2023-40791 | MED 6.3 | linux linux_kernel extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. | 0.4% | — |