58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3215 | MED 6.7 | cisco ios_xe A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual app | 0.4% | — |
| CVE-2020-3214 | MED 6.7 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vulnerability could allo | 0.4% | — |
| CVE-2018-0267 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection | 0.4% | — |
| CVE-2017-12268 | MED 6.5 | cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insufficient | 0.4% | — |
| CVE-2012-6701 | HIGH 7.8 | linux linux_kernel Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. | 0.4% | — |
| CVE-2013-3076 | MED 4.9 | linux linux_kernel The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg functi | 0.4% | — |
| CVE-2012-6541 | LOW 1.9 | linux linux_kernel The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. | 0.4% | — |
| CVE-2011-2494 | LOW 2.1 | linux linux_kernel kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password. | 0.4% | — |
| CVE-2011-2492 | LOW 1.9 | linux linux_kernel The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2 | 0.4% | — |
| CVE-2002-1189 | MED 4.6 | cisco unity_server The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding. | 0.4% | — |
| CVE-2002-0234 | LOW 2.1 | juniper netscreen_screenos NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all | 0.4% | — |
| CVE-2026-69713 | MED 4.4 | microsoft windows_10_1607 Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-33803 | MED 6.5 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due t | 0.4% | — |
| CVE-2026-14108 | HIGH 8.8 | google chrome Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) | 0.4% | — |
| CVE-2026-53248 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace pe | 0.4% | — |
| CVE-2026-48575 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-48570 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-48568 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-47656 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-45588 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-9114 | HIGH 8.8 | google chrome Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0.4% | — |
| CVE-2026-22742 | HIGH 8.6 | vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i | 0.4% | — |
| CVE-2026-23672 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-67706 | MED 5.6 | esri arcgis_server ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture en | 0.4% | — |