58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-31082 | MED 5.5 | linux linux_kernel An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability. | 0.4% | — |
| CVE-2022-45935 | MED 5.5 | apache james Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James | 0.4% | — |
| CVE-2021-3759 | MED 5.5 | debian debian_linux A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial o | 0.4% | — |
| CVE-2021-34740 | HIGH 7.4 | cisco aironet_access_point_software A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vul | 0.4% | — |
| CVE-2021-1621 | HIGH 7.4 | cisco ios_xe A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerabili | 0.4% | — |
| CVE-2021-34713 | HIGH 7.4 | cisco ios_xr A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect | 0.4% | — |
| CVE-2021-28950 | MED 5.5 | debian debian_linux An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1. | 0.4% | — |
| CVE-2019-16007 | HIGH 7.1 | cisco anyconnect_secure_mobility_client A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The | 0.4% | — |
| CVE-2019-5692 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the product uses untrusted input when calculating or using an array index, which may lead to escalation of priv | 0.4% | — |
| CVE-2019-5690 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the size of an input buffer is not validated, which may lead to denial of service or escalation of privileges. | 0.4% | — |
| CVE-2018-16882 | HIGH 8.8 | canonical ubuntu_linux A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_ | 0.4% | — |
| CVE-2018-5457 | HIGH 7.0 | vyaire carefusion_upgrade_utility A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL | 0.4% | — |
| CVE-2016-6428 | HIGH 7.8 | cisco ios_xr Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349. | 0.4% | — |
| CVE-2016-6402 | HIGH 7.8 | cisco unified_computing_system UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263. | 0.4% | — |
| CVE-2016-2558 | HIGH 8.4 | nvidia gpu_driver_r340 The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or gain privileges via unspecifie | 0.4% | — |
| CVE-2015-1900 | HIGH 7.2 | ibm infosphere_datastage IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors. | 0.4% | — |
| CVE-2014-3390 | MED 6.8 | cisco adaptive_security_appliance_software The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.3(1.1) allows local users to obtain Linux root access by leveraging administrative privileges and executing a c | 0.4% | — |
| CVE-2014-3917 | LOW 3.3 | linux linux_kernel kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value o | 0.4% | — |
| CVE-2011-4325 | MED 4.9 | linux linux_kernel The NFS implementation in Linux kernel before 2.6.31-rc6 calls certain functions without properly initializing certain data, which allows local users to cause a denial of service (NULL pointer dereference and O_DIRECT oops), as demonstrated using diotest4 from | 0.4% | — |
| CVE-2011-2678 | MED 6.8 | cisco vpn_client The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka Bug ID CSC | 0.4% | — |
| CVE-2008-1362 | HIGH 7.2 | vmware ace VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or | 0.4% | — |
| CVE-2026-79240 | HIGH 8.8 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-70338 | HIGH 7.8 | microsoft powershell Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-50510 | HIGH 7.8 | microsoft github_copilot Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-50482 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |