58.352 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-23328 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service. | 0.4% | — |
| CVE-2024-35889 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix kernel panic on unknown packet types In the very rare case where a packet type is unknown to the driver, idpf_rx_process_skb_fields would return early without calling eth_type_tran | 0.4% | — |
| CVE-2024-23454 | MED 6.2 | apache hadoop Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary dir | 0.4% | — |
| CVE-2024-21405 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-33163 | HIGH 7.5 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-20871 | HIGH 7.8 | vmware fusion VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | 0.4% | — |
| CVE-2022-22453 | HIGH 7.5 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. | 0.4% | — |
| CVE-2020-4668 | HIGH 8.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the | 0.4% | — |
| CVE-2020-3473 | HIGH 7.8 | cisco ios_xr A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is due to incorrect mapp | 0.4% | — |
| CVE-2019-20806 | MED 4.4 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75. | 0.4% | — |
| CVE-2019-1600 | MED 4.4 | cisco firepower_extensible_operating_system A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to imp | 0.4% | — |
| CVE-2018-6964 | HIGH 7.8 | vmware horizon_client VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a | 0.4% | — |
| CVE-2018-0211 | MED 4.4 | cisco identity_services_engine A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be manually rebooted to recover. The vulnerability is due to lack | 0.4% | — |
| CVE-2017-6706 | MED 5.1 | cisco prime_collaboration_provisioning A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1. | 0.4% | — |
| CVE-2017-6268 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of | 0.4% | — |
| CVE-2017-4925 | MED 5.5 | vmware esxi VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This iss | 0.4% | — |
| CVE-2016-7082 | HIGH 7.8 | vmware workstation_player VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memor | 0.4% | — |
| CVE-2014-9904 | HIGH 7.8 | debian debian_linux The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) | 0.4% | — |
| CVE-2014-8171 | MED 5.5 | linux linux_kernel The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup. | 0.4% | — |
| CVE-2011-1126 | MED 6.9 | vmware vix_api VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory. | 0.4% | — |
| CVE-2010-1641 | MED 4.6 | linux linux_kernel The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request. | 0.4% | — |
| CVE-2008-7292 | LOW 2.1 | mozilla bugzilla Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulner | 0.4% | — |
| CVE-2007-1086 | HIGH 7.2 | ibm db2_universal_database Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access." | 0.4% | — |
| CVE-2003-0631 | HIGH 7.2 | vmware gsx_server VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session. | 0.4% | — |
| CVE-2026-9006 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure | 0.4% | — |