58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-56651 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr eve | 0.3% | — |
| CVE-2024-50001 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping f | 0.3% | — |
| CVE-2024-49894 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could | 0.3% | — |
| CVE-2024-47423 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file whic | 0.3% | — |
| CVE-2024-39550 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events cause ( which can be done by repeated port flap | 0.3% | — |
| CVE-2024-39535 | MED 6.5 | juniper junos_os_evolved An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a device | 0.3% | — |
| CVE-2024-28793 | MED 4.9 | ibm engineering_workflow_management IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall | 0.3% | — |
| CVE-2024-27000 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: serial: mxs-auart: add spinlock around changing cts state The uart_handle_cts_change() function in serial_core expects the caller to hold uport->lock. For example, I have seen the below kern | 0.3% | — |
| CVE-2024-26798 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038d70 (fbdev: fbcon: Properly revert changes when vc_resize() failed) started restoring old font data upon failur | 0.3% | — |
| CVE-2023-44208 | CRIT 9.1 | acronis cyber_protect_home_office Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575. | 0.3% | — |
| CVE-2023-3937 | MED 4.8 | snowsoftware snow_license_manager Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | 0.3% | — |
| CVE-2023-24914 | HIGH 7.0 | microsoft windows_11_22h2 Win32k Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23385 | HIGH 7.0 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-49160 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash during module load unload test During purex packet handling the driver was incorrectly freeing a pre-allocated structure. Fix this by skipping that entry. System cr | 0.3% | — |
| CVE-2022-31664 | HIGH 7.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 0.3% | — |
| CVE-2022-1998 | HIGH 7.8 | fedoraproject fedora A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privil | 0.3% | — |
| CVE-2022-1729 | HIGH 7.0 | linux linux_kernel A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc. | 0.3% | — |
| CVE-2021-36183 | HIGH 7.4 | fortinet forticlient An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates. | 0.3% | — |
| CVE-2019-1734 | MED 5.5 | cisco firepower_extensible_operating_system A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to | 0.3% | — |
| CVE-2019-10127 | HIGH 8.8 | postgresql postgresql A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the defau | 0.3% | — |
| CVE-2018-15376 | MED 6.7 | cisco ios A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected de | 0.3% | — |
| CVE-2018-15375 | MED 6.7 | cisco ios A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected de | 0.3% | — |
| CVE-2018-0468 | HIGH 7.8 | cisco energy_management_suite A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability is due to the installation of the Postg | 0.3% | — |
| CVE-2017-7768 | MED 5.5 | mozilla firefox The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Servic | 0.3% | — |
| CVE-2017-6271 | MED 5.5 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation while processing block linear information which may lead to a potential d | 0.3% | — |