IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3215 MED 6.7 cisco ios_xe A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual app 0.4% —
CVE-2020-3214 MED 6.7 cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vulnerability could allo 0.4% —
CVE-2018-0267 MED 6.5 cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection 0.4% —
CVE-2017-12268 MED 6.5 cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insufficient 0.4% —
CVE-2012-6701 HIGH 7.8 linux linux_kernel Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. 0.4% —
CVE-2013-3076 MED 4.9 linux linux_kernel The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg functi 0.4% —
CVE-2012-6541 LOW 1.9 linux linux_kernel The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. 0.4% —
CVE-2011-2494 LOW 2.1 linux linux_kernel kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password. 0.4% —
CVE-2011-2492 LOW 1.9 linux linux_kernel The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2 0.4% —
CVE-2002-1189 MED 4.6 cisco unity_server The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding. 0.4% —
CVE-2002-0234 LOW 2.1 juniper netscreen_screenos NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all 0.4% —
CVE-2026-69713 MED 4.4 microsoft windows_10_1607 Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-33803 MED 6.5 juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due t 0.4% —
CVE-2026-14108 HIGH 8.8 google chrome Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) 0.4% —
CVE-2026-53248 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace pe 0.4% —
CVE-2026-48575 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-48570 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-48568 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-47656 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-45588 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-9114 HIGH 8.8 google chrome Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) 0.4% —
CVE-2026-41134 HIGH 7.8 microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings 0.4% —
CVE-2026-22742 HIGH 8.6 vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i 0.4% —
CVE-2026-23672 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4% —
CVE-2025-67706 MED 5.6 esri arcgis_server ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture en 0.4% —