58.462 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.462 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-23328 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service. | 0.4% | — |
| CVE-2025-54112 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-54111 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-54099 | HIGH 7.0 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53802 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-27196 | HIGH 7.8 | adobe premiere_pro Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0.4% | — |
| CVE-2025-27193 | HIGH 7.8 | adobe bridge Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.4% | — |
| CVE-2025-21890 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not set yet. This triggers the following warning for CONFIG_DEBUG_NET=y b | 0.4% | — |
| CVE-2024-35889 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix kernel panic on unknown packet types In the very rare case where a packet type is unknown to the driver, idpf_rx_process_skb_fields would return early without calling eth_type_tran | 0.4% | — |
| CVE-2024-21405 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-33163 | HIGH 7.5 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-20871 | HIGH 7.8 | vmware fusion VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | 0.4% | — |
| CVE-2022-22453 | HIGH 7.5 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. | 0.4% | — |
| CVE-2020-4668 | HIGH 8.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the | 0.4% | — |
| CVE-2020-3473 | HIGH 7.8 | cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is due to incorrect mapp | 0.4% | — |
| CVE-2019-20806 | MED 4.4 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75. | 0.4% | — |
| CVE-2019-1600 | MED 4.4 | cisco firepower_extensible_operating_system A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to imp | 0.4% | — |
| CVE-2018-6964 | HIGH 7.8 | vmware horizon_client VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a | 0.4% | — |
| CVE-2018-0211 | MED 4.4 | cisco identity_services_engine A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be manually rebooted to recover. The vulnerability is due to lack | 0.4% | — |
| CVE-2014-8171 | MED 5.5 | linux linux_kernel The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup. | 0.4% | — |
| CVE-2017-6268 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of | 0.4% | — |
| CVE-2017-4925 | MED 5.5 | vmware esxi VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This iss | 0.4% | — |
| CVE-2017-6706 | MED 5.1 | cisco prime_collaboration_provisioning A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1. | 0.4% | — |
| CVE-2016-7082 | HIGH 7.8 | vmware workstation_player VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memor | 0.4% | — |
| CVE-2014-9904 | HIGH 7.8 | debian debian_linux The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) | 0.4% | — |