58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0342 | HIGH 7.8 | nvidia gpu_driver All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges. | 0.3% | — |
| CVE-2017-0341 | HIGH 7.8 | nvidia gpu_driver All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial o | 0.3% | — |
| CVE-2017-0324 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges. | 0.3% | — |
| CVE-2017-0323 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges. | 0.3% | — |
| CVE-2017-0322 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a value passed from a user to the driver is not correctly validated and used as the index to an array, leading to denial of service | 0.3% | — |
| CVE-2017-0315 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an attempt to access an invalid object pointer may lead to denial of service or potential escalation of privileges | 0.3% | — |
| CVE-2017-0314 | HIGH 7.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the inte | 0.3% | — |
| CVE-2017-0308 | HIGH 8.8 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where untrusted input is used for buffer size calculation leading to denial of service or escalation of privileges. | 0.3% | — |
| CVE-2016-8461 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: Kernel-3.18. Andr | 0.3% | — |
| CVE-2014-6384 | MED 6.9 | juniper junos Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quot | 0.3% | — |
| CVE-2014-0730 | MED 6.8 | cisco unified_computing_system_central_software Cisco Unified Computing System (UCS) Central Software 1.1 and earlier allows local users to gain privileges via a CLI copy command in a local-mgmt context, aka Bug ID CSCul53128. | 0.3% | — |
| CVE-2013-1672 | MED 6.9 | mozilla firefox The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors inv | 0.3% | — |
| CVE-2007-4414 | MED 6.8 | cisco vpn_client Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box. | 0.3% | — |
| CVE-2026-77500 | HIGH 7.8 | microsoft windows_10_1607 Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-7359 | HIGH 8.8 | google chrome Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7354 | HIGH 8.8 | google chrome Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-71334 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70569 | HIGH 7.8 | microsoft windows_11_23h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70564 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69921 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69900 | HIGH 7.8 | microsoft windows_10_21h2 Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69844 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69841 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69822 | HIGH 7.8 | microsoft windows_10_1809 Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69707 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | 0.3% | — |