IT
58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.352 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2018-6969 HIGH 7.0 vmware tools VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able 0.4% —
CVE-2018-17977 MED 4.4 linux linux_kernel The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute cra 0.4% —
CVE-2017-8071 MED 5.5 linux linux_kernel drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is possible in a USB HID request callback, which allows local users to cause a denial of service (deadlock) via unspecified vectors. 0.4% —
CVE-2017-7979 HIGH 7.8 linux linux_kernel The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount underf 0.4% —
CVE-2017-4932 HIGH 7.8 vmware airwatch_launcher VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionality and privilege. Successful exploitation of this issue could result in an escala 0.4% —
CVE-2017-3762 HIGH 7.8 lenovo fingerprint_manager_pro Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with loca 0.4% —
CVE-2017-16527 MED 6.6 canonical ubuntu_linux sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device. 0.4% —
CVE-2016-7042 MED 6.2 linux linux_kernel The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of serv 0.4% —
CVE-2016-6362 HIGH 7.8 cisco aironet_access_point_software Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725. 0.4% —
CVE-2016-1340 HIGH 8.4 cisco unified_computing_system_platform_emulator Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837. 0.4% —
CVE-2014-9888 HIGH 7.8 linux linux_kernel arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not prevent executable DMA mappings, which might allow local users to gain privileges via a crafted applicati 0.4% —
CVE-2014-3391 MED 6.8 cisco adaptive_security_appliance_software Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by placing a Trojan horse library file in external memory, leading to library use after device reload because of an 0.4% —
CVE-2012-2752 HIGH 7.2 vmware vma Untrusted search path vulnerability in VMware vMA 4.x and 5.x before 5.0.0.2 allows local users to gain privileges via a Trojan horse DLL in the current working directory. 0.4% —
CVE-2011-2905 MED 6.2 linux linux_kernel Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory. 0.4% —
CVE-2010-5331 HIGH 7.8 linux linux_kernel In the Linux kernel before 2.6.34, a range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (buffer overflow) problem. NOTE: At least one Linux maintainer believes that this CVE is incorrectly assigned and should be rejected because t 0.4% —
CVE-2010-4529 LOW 2.1 linux linux_kernel Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt cal 0.4% —
CVE-2010-3874 MED 4.0 debian debian_linux Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service 0.4% —
CVE-2010-3442 MED 4.7 canonical ubuntu_linux Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted ( 0.4% —
CVE-2009-2909 MED 4.9 linux linux_kernel Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation. 0.4% —
CVE-2002-0570 LOW 2.1 linux linux_kernel The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key. 0.4% —
CVE-2026-9126 HIGH 8.8 google chrome Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2026-9118 HIGH 8.8 google chrome Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-9112 HIGH 8.8 google chrome Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-72945 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-72937 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. 0.4% —