58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-28796 | HIGH 7.0 | fedoraproject fedora jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | 0.3% | — |
| CVE-2022-26878 | MED 5.5 | linux linux_kernel drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed). | 0.3% | — |
| CVE-2021-28714 | MED 6.5 | debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's | 0.3% | — |
| CVE-2021-1558 | MED 6.0 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions duri | 0.3% | — |
| CVE-2021-1557 | MED 6.0 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions duri | 0.3% | — |
| CVE-2021-1514 | HIGH 7.8 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to insufficient input valid | 0.3% | — |
| CVE-2020-27129 | MED 6.7 | cisco sd-wan_vmanage A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges. The vulnerability is due to improper validation of commands to | 0.3% | — |
| CVE-2019-3652 | MED 5.0 | mcafee endpoint_security Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the | 0.3% | — |
| CVE-2019-3622 | HIGH 8.2 | mcafee data_loss_prevention_endpoint Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder a | 0.3% | — |
| CVE-2017-12332 | MED 4.4 | cisco nx-os A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could ex | 0.3% | — |
| CVE-2016-8824 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, l | 0.3% | — |
| CVE-2016-8821 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where improper access controls may allow a user to access arbitrary physical memory, leading to an escalation of privileges. | 0.3% | — |
| CVE-2015-0755 | MED 6.8 | cisco anyconnect_secure_mobility_client The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797. | 0.3% | — |
| CVE-2010-5313 | MED 4.9 | linux linux_kernel Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842. | 0.3% | — |
| CVE-2007-6209 | MED 4.6 | zsh zsh Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | 0.3% | — |
| CVE-2005-3527 | MED 4.0 | linux linux_kernel Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP. | 0.3% | — |
| CVE-2026-76449 | MED 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficie | 0.3% | — |
| CVE-2026-76448 | MED 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficie | 0.3% | — |
| CVE-2026-7361 | HIGH 8.8 | google chrome Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-69467 | HIGH 7.8 | microsoft windows_10_21h2 Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-59085 | CRIT 9.1 | apache cloudstack Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended | 0.3% | — |
| CVE-2026-42916 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42837 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42828 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34343 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |