IT
58.378 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.378 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-5865 MED 4.8 f5 nginx_controller In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks. 0.4% —
CVE-2020-10768 MED 5.5 linux linux_kernel A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system t 0.4% —
CVE-2019-19166 HIGH 7.8 tobesoft xplatform Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution. 0.4% —
CVE-2018-5486 HIGH 7.8 netapp oncommand_unified_manager NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code. 0.4% —
CVE-2017-9480 MED 5.5 cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows local users (e.g., users who have command access as a consequence of CVE-2017-9479 exploitation) to read arbitrary files via UPnP access to /var/ 0.4% —
CVE-2017-5669 HIGH 7.8 canonical ubuntu_linux The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap s 0.4% —
CVE-2016-8817 HIGH 7.8 nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer 0.4% —
CVE-2016-6258 HIGH 8.8 citrix xenserver The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. 0.4% —
CVE-2016-1420 HIGH 7.8 cisco application_infrastructure_controller The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCuz72347. 0.4% —
CVE-2013-2547 LOW 2.1 linux linux_kernel The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel 0.4% —
CVE-2012-5445 MED 6.8 cisco skinny_client_control_protocol_software The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of serv 0.4% —
CVE-2012-4106 MED 6.8 cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows local users to gain privileges and execute arbitrary commands via an unspecified script-execution approach, aka 0.4% —
CVE-2012-1090 MED 5.5 linux linux_kernel The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO. 0.4% —
CVE-2011-0710 LOW 2.1 linux linux_kernel The task_show_regs function in arch/s390/kernel/traps.c in the Linux kernel before 2.6.38-rc4-next-20110216 on the s390 platform allows local users to obtain the values of the registers of an arbitrary process by reading a status file under /proc/. 0.4% —
CVE-2010-0007 LOW 2.1 linux linux_kernel net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restriction 0.4% —
CVE-2009-3290 HIGH 7.2 linux linux_kernel The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a d 0.4% —
CVE-2006-0742 MED 4.6 linux linux_kernel The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing user fault 0.4% —
CVE-2001-1400 LOW 2.1 linux linux_kernel Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock). 0.4% —
CVE-2001-1394 LOW 2.1 linux linux_kernel Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service. 0.4% —
CVE-2026-69690 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4% —
CVE-2026-40413 HIGH 7.4 microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability 0.4% —
CVE-2026-19306 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload 0.4% —
CVE-2025-62572 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62571 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-62467 HIGH 7.8 microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —