58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20037 | MED 5.4 | cisco industrial_network_director A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An att | 0.4% | — |
| CVE-2022-44699 | MED 5.5 | microsoft azure_network_watcher_agent Azure Network Watcher Agent Security Feature Bypass Vulnerability | 0.4% | — |
| CVE-2022-34706 | HIGH 7.8 | microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2021-23175 | HIGH 8.2 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information d | 0.4% | — |
| CVE-2020-3556 | HIGH 7.3 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a la | 0.4% | — |
| CVE-2020-25220 | HIGH 7.8 | linux linux_kernel The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature. | 0.4% | — |
| CVE-2019-12661 | MED 6.7 | cisco ios_xe A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerabilit | 0.4% | — |
| CVE-2019-1770 | MED 6.7 | cisco ns-ox A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to | 0.4% | — |
| CVE-2017-12192 | MED 5.5 | linux linux_kernel The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of servic | 0.4% | — |
| CVE-2017-11159 | HIGH 7.8 | synology photo_station_uploader Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, ( | 0.4% | — |
| CVE-2017-8070 | HIGH 7.8 | linux linux_kernel drivers/net/usb/catc.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by lever | 0.4% | — |
| CVE-2015-2042 | MED 4.6 | linux linux_kernel net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry. | 0.4% | — |
| CVE-2013-1943 | HIGH 7.8 | canonical ubuntu_linux The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information fr | 0.4% | — |
| CVE-2012-1510 | HIGH 7.2 | vmware esx Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors. | 0.4% | — |
| CVE-2006-1859 | LOW 2.1 | linux linux_kernel Memory leak in __setlease in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an "uninitialised return value," aka "slab leak." | 0.4% | — |
| CVE-2026-25700 | HIGH 7.2 | apache answer Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactiva | 0.4% | — |
| CVE-2026-35440 | MED 5.5 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2025-20276 | LOW 3.8 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.&nb | 0.4% | — |
| CVE-2022-20626 | MED 5.5 | cisco prime_access_registrar A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid creden | 0.4% | — |
| CVE-2024-37028 | MED 5.3 | f5 big-ip_next_central_manager BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2023-43018 | MED 5.9 | ibm cics_tx IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163. | 0.4% | — |
| CVE-2023-40791 | MED 6.3 | linux linux_kernel extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. | 0.4% | — |
| CVE-2023-28225 | HIGH 7.8 | microsoft windows_10_1507 Windows NTLM Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-20153 | MED 6.0 | cisco identity_services_engine Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnera | 0.4% | — |
| CVE-2023-20152 | MED 6.0 | cisco identity_services_engine Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnera | 0.4% | — |