58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22412 | MED 4.6 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019. | 0.3% | — |
| CVE-2021-1536 | MED 4.8 | cisco webex_meetings_desktop A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on | 0.3% | — |
| CVE-2020-3541 | MED 4.4 | cisco webex_meetings A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The | 0.3% | — |
| CVE-2019-8454 | HIGH 7.0 | checkpoint endpoint_security A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will | 0.3% | — |
| CVE-2017-12315 | MED 6.0 | cisco hyperflex_hx_data_platform A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system log files. The attacker would have to be a | 0.3% | — |
| CVE-2016-6470 | HIGH 7.8 | cisco hybrid_media_service A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb81344. Known Affected Releases: 1.0. | 0.3% | — |
| CVE-2016-5295 | HIGH 7.8 | mozilla firefox This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MF | 0.3% | — |
| CVE-2015-4170 | MED 4.7 | linux linux_kernel Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during sh | 0.3% | — |
| CVE-2013-1172 | MED 6.6 | cisco anyconnect_secure_mobility_client The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153. | 0.3% | — |
| CVE-2012-4206 | MED 6.9 | mozilla firefox Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory. | 0.3% | — |
| CVE-2010-5179 | MED 6.2 | trendmicro internet_security_2010 Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware de | 0.3% | — |
| CVE-2002-0225 | MED 4.6 | cisco tacacs\+ tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files. | 0.3% | — |
| CVE-2026-64235 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform (eg: Skylake), with retbleed=stuff, registe | 0.3% | — |
| CVE-2026-59654 | HIGH 7.5 | apache cloudstack Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to e | 0.3% | — |
| CVE-2026-59286 | HIGH 8.1 | vmware spring_for_graphql The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Sp | 0.3% | — |
| CVE-2026-58177 | HIGH 8.1 | apache traffic_server The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. | 0.3% | — |
| CVE-2026-54665 | MED 5.3 | apache nifi Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application pro | 0.3% | — |
| CVE-2026-20301 | HIGH 8.6 | cisco ios A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition o | 0.3% | — |
| CVE-2025-60717 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59515 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59504 | HIGH 7.3 | microsoft azure_monitor_agent Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2025-20216 | MED 4.7 | cisco catalyst_sd-wan_manager A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitizatio | 0.3% | — |
| CVE-2025-14974 | MED 5.7 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR). | 0.3% | — |
| CVE-2025-13726 | MED 5.3 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks aga | 0.3% | — |
| CVE-2024-8035 | MED 4.3 | google chrome Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |