IT
57.288 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.288 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-1476 MED 6.7 cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected d 0.5%
CVE-2019-5535 MED 4.7 vmware fusion VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7. 0.5%
CVE-2019-19954 HIGH 7.3 signal signal-desktop Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. 0.5%
CVE-2019-11190 MED 4.7 linux linux_kernel The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading 0.5%
CVE-2018-15402 MED 5.4 cisco enterprise_network_virtualization_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests wit 0.5%
CVE-2016-2549 MED 6.2 linux linux_kernel sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call. 0.5%
CVE-2011-4098 LOW 1.9 linux linux_kernel The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory. 0.5%
CVE-2011-3209 MED 4.9 linux linux_kernel The div_long_long_rem implementation in include/asm-x86/div64.h in the Linux kernel before 2.6.26 on the x86 platform allows local users to cause a denial of service (Divide Error Fault and panic) via a clock_gettime system call. 0.5%
CVE-2003-1161 HIGH 7.2 linux linux_kernel exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function. 0.5%
CVE-2026-64607 MED 5.3 apache httpclient HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not a 0.5%
CVE-2026-57101 HIGH 7.1 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.5%
CVE-2026-55139 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-43074 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concur 0.5%
CVE-2026-21860 MED 5.3 palletsprojects werkzeug Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, 0.5%
CVE-2025-59204 MED 5.5 microsoft windows_10_1809 Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-55682 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2025-55337 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2025-55325 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-54915 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-21927 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a p 0.5%
CVE-2024-38337 CRIT 9.1 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments. 0.5%
CVE-2024-21304 MED 4.1 microsoft windows_10_1809 Trusted Compute Base Elevation of Privilege Vulnerability 0.5%
CVE-2022-39843 HIGH 7.8 lotus_1-2-3_project lotus_1-2-3 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing r 0.5%
CVE-2022-35828 HIGH 7.8 microsoft defender_for_endpoint Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability 0.5%
CVE-2022-23511 HIGH 7.1 amazon cloudwatch_agent A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, 0.5%