IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-3388 MED 4.1 paloaltonetworks pan-os A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive res 0.3% —
CVE-2022-35669 MED 5.5 adobe acrobat Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t 0.3% —
CVE-2022-34252 MED 5.5 adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitat 0.3% —
CVE-2021-43204 MED 4.4 fortinet forticlient A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory acc 0.3% —
CVE-2021-42011 HIGH 7.8 trendmicro apex_one An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute 0.3% —
CVE-2019-15925 HIGH 7.8 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c. 0.3% —
CVE-2019-3621 MED 6.8 mcafee data_loss_prevention_endpoint Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the 0.3% —
CVE-2016-6276 HIGH 7.8 citrix linux_virtual_delivery_agent Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors. 0.3% —
CVE-2013-5522 MED 6.8 cisco catalyst_3750-x Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. 0.3% —
CVE-2013-1215 MED 6.8 cisco 5500_series_adaptive_security_appliance The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via unspecified vectors, aka Bug ID CSCuf85295. 0.3% —
CVE-2012-4542 MED 4.6 linux linux_kernel block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcode 0.3% —
CVE-2011-4080 MED 4.0 linux linux_kernel The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring bu 0.3% —
CVE-2009-1184 MED 4.4 linux linux_kernel The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, w 0.3% —
CVE-2007-1589 LOW 2.1 truecrypt_foundation truecrypt TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user. 0.3% —
CVE-2026-98115 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared se 0.3% —
CVE-2026-85921 HIGH 8.2 microsoft windows_11_26h1 Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-83939 HIGH 8.2 microsoft windows_11_26h1 Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-81354 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72962 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72961 HIGH 8.2 microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72958 HIGH 8.2 microsoft windows_11_24h2 Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-72935 MED 6.7 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-71339 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69906 HIGH 8.2 microsoft windows_10_1607 Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69846 HIGH 8.2 microsoft windows_10_1607 Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —