58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-3388 | MED 4.1 | paloaltonetworks pan-os A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive res | 0.3% | — |
| CVE-2022-35669 | MED 5.5 | adobe acrobat Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t | 0.3% | — |
| CVE-2022-34252 | MED 5.5 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitat | 0.3% | — |
| CVE-2021-43204 | MED 4.4 | fortinet forticlient A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory acc | 0.3% | — |
| CVE-2021-42011 | HIGH 7.8 | trendmicro apex_one An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute | 0.3% | — |
| CVE-2019-15925 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c. | 0.3% | — |
| CVE-2019-3621 | MED 6.8 | mcafee data_loss_prevention_endpoint Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the | 0.3% | — |
| CVE-2016-6276 | HIGH 7.8 | citrix linux_virtual_delivery_agent Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors. | 0.3% | — |
| CVE-2013-5522 | MED 6.8 | cisco catalyst_3750-x Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. | 0.3% | — |
| CVE-2013-1215 | MED 6.8 | cisco 5500_series_adaptive_security_appliance The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via unspecified vectors, aka Bug ID CSCuf85295. | 0.3% | — |
| CVE-2012-4542 | MED 4.6 | linux linux_kernel block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcode | 0.3% | — |
| CVE-2011-4080 | MED 4.0 | linux linux_kernel The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring bu | 0.3% | — |
| CVE-2009-1184 | MED 4.4 | linux linux_kernel The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, w | 0.3% | — |
| CVE-2007-1589 | LOW 2.1 | truecrypt_foundation truecrypt TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user. | 0.3% | — |
| CVE-2026-98115 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared se | 0.3% | — |
| CVE-2026-85921 | HIGH 8.2 | microsoft windows_11_26h1 Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83939 | HIGH 8.2 | microsoft windows_11_26h1 Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-81354 | HIGH 8.2 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72962 | HIGH 8.2 | microsoft windows_10_1809 Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72961 | HIGH 8.2 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72958 | HIGH 8.2 | microsoft windows_11_24h2 Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72935 | MED 6.7 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71339 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69906 | HIGH 8.2 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69846 | HIGH 8.2 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |