58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-59255 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59207 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-58728 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55677 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55339 | HIGH 7.8 | microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50175 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-50152 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-0130 | HIGH 7.5 | paloaltonetworks pan-os A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate | 0.4% | — |
| CVE-2025-0440 | MED 6.5 | google chrome Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2024-41761 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query. | 0.4% | — |
| CVE-2024-49526 | HIGH 7.8 | adobe animate Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic | 0.4% | — |
| CVE-2024-39518 | HIGH 7.5 | juniper junos A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS). Wh | 0.4% | — |
| CVE-2023-47078 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0.4% | — |
| CVE-2023-47061 | MED 5.5 | adobe dimension Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 0.4% | — |
| CVE-2022-34865 | MED 4.8 | f5 big-ip_access_policy_manager In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reac | 0.4% | — |
| CVE-2022-20651 | MED 5.5 | cisco adaptive_security_device_manager A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation enviro | 0.4% | — |
| CVE-2022-22008 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2022-0487 | MED 5.5 | debian debian_linux A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions | 0.4% | — |
| CVE-2021-28039 | MED 6.5 | linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical | 0.4% | — |
| CVE-2021-1372 | MED 5.5 | cisco webex_meetings A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared mem | 0.4% | — |
| CVE-2019-4606 | HIGH 7.8 | ibm db2_high_performance_unload_load IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute | 0.4% | — |
| CVE-2019-1604 | HIGH 7.8 | cisco nx-os A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to an incorrect authorization check of user accounts and t | 0.4% | — |
| CVE-2014-9731 | LOW 2.1 | linux linux_kernel The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesyste | 0.4% | — |
| CVE-2014-8159 | MED 6.9 | canonical ubuntu_linux The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical me | 0.4% | — |
| CVE-2013-0231 | MED 4.9 | linux linux_kernel The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log me | 0.4% | — |