58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-27000 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: serial: mxs-auart: add spinlock around changing cts state The uart_handle_cts_change() function in serial_core expects the caller to hold uport->lock. For example, I have seen the below kern | 0.3% | — |
| CVE-2024-26798 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038d70 (fbdev: fbcon: Properly revert changes when vc_resize() failed) started restoring old font data upon failur | 0.3% | — |
| CVE-2023-44208 | CRIT 9.1 | acronis cyber_protect_home_office Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575. | 0.3% | — |
| CVE-2023-3937 | MED 4.8 | snowsoftware snow_license_manager Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | 0.3% | — |
| CVE-2023-24914 | HIGH 7.0 | microsoft windows_11_22h2 Win32k Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23385 | HIGH 7.0 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-1729 | HIGH 7.0 | linux linux_kernel A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc. | 0.3% | — |
| CVE-2022-31664 | HIGH 7.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 0.3% | — |
| CVE-2022-1998 | HIGH 7.8 | fedoraproject fedora A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privil | 0.3% | — |
| CVE-2021-36183 | HIGH 7.4 | fortinet forticlient An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates. | 0.3% | — |
| CVE-2019-10127 | HIGH 8.8 | postgresql postgresql A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the defau | 0.3% | — |
| CVE-2019-1734 | MED 5.5 | cisco firepower_extensible_operating_system A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to | 0.3% | — |
| CVE-2018-0468 | HIGH 7.8 | cisco energy_management_suite A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability is due to the installation of the Postg | 0.3% | — |
| CVE-2018-15376 | MED 6.7 | cisco ios A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected de | 0.3% | — |
| CVE-2018-15375 | MED 6.7 | cisco ios A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected de | 0.3% | — |
| CVE-2017-7768 | MED 5.5 | mozilla firefox The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Servic | 0.3% | — |
| CVE-2017-6271 | MED 5.5 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation while processing block linear information which may lead to a potential d | 0.3% | — |
| CVE-2017-1508 | MED 6.7 | ibm informix_dynamic_server IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620. | 0.3% | — |
| CVE-2016-5329 | MED 5.5 | vmware fusion VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors. | 0.3% | — |
| CVE-2016-6413 | HIGH 7.8 | cisco application_policy_infrastructure_controller The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496. | 0.3% | — |
| CVE-2013-0349 | LOW 1.9 | linux linux_kernel The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD | 0.3% | — |
| CVE-2011-2569 | MED 6.8 | cisco nx-os Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr446 | 0.3% | — |
| CVE-2006-7037 | MED 4.4 | mathsoft mathcad Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the p | 0.3% | — |
| CVE-2026-46332 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer before parsing bootloader packets. The helper can keep le | 0.3% | — |
| CVE-2026-10906 | HIGH 7.5 | google chrome Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |