58.273 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.273 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-34247 | HIGH 7.8 | adobe indesign Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 0.3% | — |
| CVE-2021-1060 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (pr | 0.3% | — |
| CVE-2021-1058 | HIGH 7.1 | nvidia virtual_gpu_manager NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 | 0.3% | — |
| CVE-2020-5674 | HIGH 7.8 | epson album_print Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 0.3% | — |
| CVE-2020-2049 | HIGH 7.8 | paloaltonetworks cortex_xdr_agent A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create | 0.3% | — |
| CVE-2019-6648 | MED 4.4 | f5 container_ingress_service On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Dec | 0.3% | — |
| CVE-2017-6775 | MED 5.7 | cisco asr_5000_software A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to elevate their privileges to admin-level privileges. The vulnerability is due to incorrect | 0.3% | — |
| CVE-2017-3806 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. M | 0.3% | — |
| CVE-2017-12351 | MED 5.7 | cisco nx-os A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perform th | 0.3% | — |
| CVE-2016-5412 | MED 6.5 | linux linux_kernel arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence | 0.3% | — |
| CVE-2016-3713 | HIGH 7.1 | linux linux_kernel The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service | 0.3% | — |
| CVE-2012-6538 | LOW 1.9 | linux linux_kernel The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN ca | 0.3% | — |
| CVE-2012-4082 | MED 6.8 | cisco unified_computing_system MCTools in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to gain privileges by entering crafted command-line parameters on a Fabric Interconnect device, aka Bug ID CSCtg20749. | 0.3% | — |
| CVE-2012-2133 | MED 4.0 | linux linux_kernel Use-after-free vulnerability in the Linux kernel before 3.3.6, when huge pages are enabled, allows local users to cause a denial of service (system crash) or possibly gain privileges by interacting with a hugetlbfs filesystem, as demonstrated by a umount opera | 0.3% | — |
| CVE-2026-81386 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-56155 | HIGH 7.8 | microsoft windows_10_1607 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | 0.3% | |
| CVE-2026-53070 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmit_skb() udp_tunnel_xmit_skb() / udp_tunnel6_xmit_skb() are expected to run with BH disabled. After commit 6f1a9140ecda ("add xmit recursion lim | 0.3% | — |
| CVE-2026-42926 | MED 5.8 | f5 nginx_gateway_fabric When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached E | 0.3% | — |
| CVE-2026-34476 | HIGH 7.1 | apache skywalking_mcp Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | 0.3% | — |
| CVE-2025-59202 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55689 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55686 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55685 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55331 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53717 | HIGH 7.0 | microsoft windows_11_22h2 Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |