58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22405 | MED 5.9 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle | 0.5% | — |
| CVE-2020-29014 | MED 6.3 | fortinet fortisandbox A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of FortiSandbox before 3.2.2 may allow an authenticated attacker to bring the system into an unresponsive state via specifically orchestrated seq | 0.5% | — |
| CVE-2019-25045 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. | 0.5% | — |
| CVE-2019-19083 | MED 4.7 | canonical ubuntu_linux Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption). This affects the dce112_clock_source_create() function in drivers/gpu/drm/ | 0.5% | — |
| CVE-2019-5522 | HIGH 7.1 | vmware tools VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administra | 0.5% | — |
| CVE-2019-1791 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is | 0.5% | — |
| CVE-2019-1591 | HIGH 7.8 | cisco nx-os A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insufficient sanitization | 0.5% | — |
| CVE-2017-6606 | MED 6.4 | cisco ios_xe A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Informa | 0.5% | — |
| CVE-2026-50370 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-53216 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buf | 0.5% | — |
| CVE-2026-53215 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer | 0.5% | — |
| CVE-2026-43406 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being less | 0.5% | — |
| CVE-2026-43304 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buffer in process_auth_done() and generally has a sane length. T | 0.5% | — |
| CVE-2026-31478 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add support for read compound"), response buffer management was chang | 0.5% | — |
| CVE-2023-44184 | MED 6.5 | juniper junos An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a spec | 0.5% | — |
| CVE-2023-35332 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Protocol Security Feature Bypass | 0.5% | — |
| CVE-2022-34336 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu | 0.5% | — |
| CVE-2021-34773 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Un | 0.5% | — |
| CVE-2020-27820 | MED 4.7 | fedoraproject fedora A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver). | 0.5% | — |
| CVE-2021-1268 | HIGH 7.4 | cisco ios_xr A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists bec | 0.5% | — |
| CVE-2020-8146 | HIGH 7.8 | ui unifi_video In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and ad | 0.5% | — |
| CVE-2013-2146 | MED 4.7 | linux linux_kernel arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an incorrect bitmask, which allows local users to cause a denial of service (general protection fault and system crash) by atte | 0.5% | — |
| CVE-2009-0269 | MED 4.9 | canonical ubuntu_linux fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to | 0.5% | — |
| CVE-2026-78516 | MED 4.3 | microsoft windows_10_1607 Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack. | 0.5% | — |
| CVE-2026-78455 | MED 4.3 | microsoft windows_10_1607 Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. | 0.5% | — |