IT
57.298 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-39343 MED 5.6 microsoft azure_rtos_filex Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow an 0.8%
CVE-2022-29901 MED 5.6 debian debian_linux Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary 4.8%
CVE-2022-22713 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.7%
CVE-2022-22712 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2021-43246 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2021-42299 MED 5.6 microsoft surface_pro_3_firmware Microsoft Surface Pro 3 Security Feature Bypass Vulnerability 0.9%
CVE-2020-7807 MED 5.6 lg ipsfullhd A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT___ 0.2%
CVE-2020-3432 MED 5.6 cisco anyconnect_secure_mobility_client A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directo 0.2%
CVE-2020-29012 MED 5.6 fortinet fortisandbox An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain 0.5%
CVE-2020-14390 MED 5.6 debian debian_linux A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled o 0.3%
CVE-2019-7308 MED 5.6 canonical ubuntu_linux kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. 0.5%
CVE-2019-3887 MED 5.6 canonical ubuntu_linux A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest c 0.4%
CVE-2019-3610 MED 5.6 mcafee true_key Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware. 0.3%
CVE-2019-15902 MED 5.6 debian debian_linux A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrac 0.6%
CVE-2019-1171 MED 5.6 microsoft windows_10 An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker 1.4%
CVE-2019-1125 MED 5.6 microsoft windows_10 An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, 4.5%
CVE-2019-0072 MED 5.6 juniper sbr_carrier An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prio 0.2%
CVE-2018-8479 MED 5.6 microsoft c_software_development_kit A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK. 2.1%
CVE-2018-8119 MED 5.6 microsoft c_software_development_kit A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. 1.2%
CVE-2018-3665 MED 5.6 canonical ubuntu_linux System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. 0.6%
CVE-2018-19965 MED 5.6 citrix xenserver An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorr 0.4%
CVE-2018-0888 MED 5.6 microsoft windows_10 The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 a 1.4%
CVE-2018-0087 MED 5.6 cisco asyncos A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability i 1.8%
CVE-2017-5753 MED 5.6 arm cortex-a12_firmware Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. 93.8%
CVE-2017-12553 MED 5.6 hp system_management_homepage A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. 0.3%