IT
58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2016-8820 MED 6.1 nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source 0.3%
CVE-2015-0603 MED 4.6 cisco unified_ip_phones_9900_series_firmware Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474. 0.3%
CVE-2015-0601 MED 4.6 cisco unified_ip_phones_9951_firmware Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790. 0.3%
CVE-2008-0163 MED 4.4 linux linux_kernel Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc. 0.3%
CVE-2007-1089 HIGH 7.2 ibm db2_universal_database IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors. 0.3%
CVE-2007-1056 HIGH 7.2 vmware workstation VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools ser 0.3%
CVE-2026-69895 MED 4.7 microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-69853 MED 4.7 microsoft windows_10_1607 Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-69483 MED 4.7 microsoft windows_10_1607 Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-69316 MED 4.7 microsoft windows_10_1607 Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-68833 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. 0.3%
CVE-2026-54127 HIGH 7.4 microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-50749 MED 6.5 apache answer Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. 0.3%
CVE-2026-48912 MED 6.5 apache answer Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs 0.3%
CVE-2026-40419 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-3061 CRIT 9.1 google chrome Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-27316 LOW 2.7 fortinet fortisandbox A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side in 0.3%
CVE-2026-20831 HIGH 7.8 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20826 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-10917 HIGH 8.3 google chrome Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-10911 HIGH 8.3 google chrome Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2025-66495 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be ac 0.3%
CVE-2025-66494 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacke 0.3%
CVE-2025-66493 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been free 0.3%
CVE-2025-59187 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%