58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-26665 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2024-0137 | MED 5.5 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is config | 0.3% | — |
| CVE-2024-38069 | HIGH 7.0 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0.3% | — |
| CVE-2024-27075 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: avoid stack overflow warnings with clang A previous patch worked around a KASAN issue in stv0367, now a similar problem showed up with clang: drivers/media/dvb-fronten | 0.3% | — |
| CVE-2024-26633 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken. Reading frag_off can only be done if we pulled enou | 0.3% | — |
| CVE-2023-44188 | MED 5.3 | juniper junos A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Strea | 0.3% | — |
| CVE-2019-16471 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.3% | — |
| CVE-2023-3297 | HIGH 8.1 | canonical accountsservice In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | 0.3% | — |
| CVE-2022-1789 | MED 6.8 | debian debian_linux With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. | 0.3% | — |
| CVE-2021-43940 | HIGH 7.8 | atlassian confluence_data_center Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations | 0.3% | — |
| CVE-2020-24367 | HIGH 7.8 | bluestacks bluestacks Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user. | 0.3% | — |
| CVE-2019-0004 | MED 5.5 | juniper advanced_threat_prevention On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3. | 0.3% | — |
| CVE-2018-0275 | MED 6.7 | cisco identity_services_engine A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could | 0.3% | — |
| CVE-2016-9197 | MED 6.7 | cisco mobility_services_engine A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers could allow an authenticated, local attacker to obtain access to the underlying operating system shell with root-level privileges. More Inform | 0.3% | — |
| CVE-2016-6110 | MED 6.5 | ibm tivoli_storage_manager IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user. | 0.3% | — |
| CVE-2010-4076 | LOW 1.9 | linux linux_kernel The rs_ioctl function in drivers/char/amiserial.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT | 0.3% | — |
| CVE-2006-4663 | HIGH 7.8 | linux linux_kernel The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local users to insert Trojan horse source code that would be used dur | 0.3% | — |
| CVE-2026-76191 | HIGH 8.2 | adobe animate Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary | 0.3% | — |
| CVE-2026-42248 | CRIT 9.8 | ollama ollama Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust | 0.3% | — |
| CVE-2025-38637 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an assertion that fails under certain conditions when SKBPRIO is use | 0.3% | — |
| CVE-2025-27204 | MED 5.5 | adobe after_effects After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0.3% | — |
| CVE-2025-27202 | MED 5.5 | adobe animate Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue req | 0.3% | — |
| CVE-2025-27201 | MED 5.5 | adobe animate Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue req | 0.3% | — |
| CVE-2025-27187 | MED 5.5 | adobe after_effects After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0.3% | — |
| CVE-2025-27186 | MED 5.5 | adobe after_effects After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0.3% | — |