58.434 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.434 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-5909 | MED 5.4 | f5 nginx_controller In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified. | 0.4% | — |
| CVE-2019-19166 | HIGH 7.8 | tobesoft xplatform Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution. | 0.4% | — |
| CVE-2020-5865 | MED 4.8 | f5 nginx_controller In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks. | 0.4% | — |
| CVE-2018-5486 | HIGH 7.8 | netapp oncommand_unified_manager NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code. | 0.4% | — |
| CVE-2017-9480 | MED 5.5 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows local users (e.g., users who have command access as a consequence of CVE-2017-9479 exploitation) to read arbitrary files via UPnP access to /var/ | 0.4% | — |
| CVE-2017-5669 | HIGH 7.8 | canonical ubuntu_linux The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap s | 0.4% | — |
| CVE-2016-8817 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer | 0.4% | — |
| CVE-2016-6258 | HIGH 8.8 | citrix xenserver The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. | 0.4% | — |
| CVE-2016-1420 | HIGH 7.8 | cisco application_infrastructure_controller The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCuz72347. | 0.4% | — |
| CVE-2012-4106 | MED 6.8 | cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows local users to gain privileges and execute arbitrary commands via an unspecified script-execution approach, aka | 0.4% | — |
| CVE-2013-2547 | LOW 2.1 | linux linux_kernel The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel | 0.4% | — |
| CVE-2012-5445 | MED 6.8 | cisco skinny_client_control_protocol_software The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of serv | 0.4% | — |
| CVE-2012-1090 | MED 5.5 | linux linux_kernel The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO. | 0.4% | — |
| CVE-2011-0710 | LOW 2.1 | linux linux_kernel The task_show_regs function in arch/s390/kernel/traps.c in the Linux kernel before 2.6.38-rc4-next-20110216 on the s390 platform allows local users to obtain the values of the registers of an arbitrary process by reading a status file under /proc/. | 0.4% | — |
| CVE-2010-0007 | LOW 2.1 | linux linux_kernel net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restriction | 0.4% | — |
| CVE-2009-3290 | HIGH 7.2 | linux linux_kernel The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a d | 0.4% | — |
| CVE-2006-0742 | MED 4.6 | linux linux_kernel The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing user fault | 0.4% | — |
| CVE-2001-1400 | LOW 2.1 | linux linux_kernel Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock). | 0.4% | — |
| CVE-2001-1394 | LOW 2.1 | linux linux_kernel Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service. | 0.4% | — |
| CVE-2026-20249 | HIGH 8.6 | A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthentica | 0.4% | — |
| CVE-2026-53309 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range of q | 0.4% | — |
| CVE-2026-52945 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" This reverts commit 933466fc50a8e4eb167acbd0d8ec96a078462e9c which is commit db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e upstream. We have had | 0.4% | — |
| CVE-2026-45606 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-44805 | MED 5.5 | microsoft windows_server_2019 Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-42915 | MED 5.5 | microsoft windows_10_21h2 Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. | 0.4% | — |