58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-20327 | HIGH 7.4 | cisco ios_xr A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service | 0.3% | — |
| CVE-2023-20003 | MED 4.7 | cisco business_140ac_access_point_firmware A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with | 0.3% | — |
| CVE-2022-22217 | MED 6.1 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packet | 0.3% | — |
| CVE-2022-22479 | HIGH 8.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | 0.3% | — |
| CVE-2022-30702 | MED 5.5 | trendmicro security Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine. | 0.3% | — |
| CVE-2022-1516 | MED 5.5 | debian debian_linux A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local | 0.3% | — |
| CVE-2021-4150 | MED 5.5 | linux linux_kernel A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails | 0.3% | — |
| CVE-2020-10720 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system. | 0.3% | — |
| CVE-2020-3379 | HIGH 7.8 | cisco sd-wan_firmware A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this | 0.3% | — |
| CVE-2019-1866 | LOW 3.1 | cisco webex_business_suite_39 Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host header values. An attacker with a privile | 0.3% | — |
| CVE-2019-4448 | HIGH 7.8 | ibm db2_high_performance_unload_load IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libra | 0.3% | — |
| CVE-2019-0029 | HIGH 8.8 | juniper advanced_threat_prevention Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the Splunk server. This issue affects Juniper ATP 5.0 versions prior to 5.0.3. | 0.3% | — |
| CVE-2019-0021 | HIGH 7.1 | juniper advanced_threat_prevention On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4. | 0.3% | — |
| CVE-2016-5293 | MED 5.5 | debian debian_linux When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. | 0.3% | — |
| CVE-2017-16526 | HIGH 7.8 | canonical ubuntu_linux drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.3% | — |
| CVE-2015-6394 | MED 4.9 | cisco nx-os The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of service (device crash) via crafted USB parameters, aka Bug ID CSCus89408. | 0.3% | — |
| CVE-2015-0663 | MED 6.6 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392. | 0.3% | — |
| CVE-2014-9529 | MED 6.9 | canonical ubuntu_linux Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger a | 0.3% | — |
| CVE-2013-2890 | MED 4.7 | linux linux_kernel drivers/hid/hid-sony.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SONY is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device. | 0.3% | — |
| CVE-2026-14996 | HIGH 8.2 | ibm aspera_faspex IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. | 0.3% | — |
| CVE-2026-48578 | HIGH 7.9 | microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45654 | HIGH 7.9 | microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-7929 | HIGH 7.5 | google chrome Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-32220 | MED 4.4 | microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-5284 | HIGH 7.5 | google chrome Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |