58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-29113 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2019-16229 | MED 4.1 | canonical ubuntu_linux drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id | 0.4% | — |
| CVE-2018-20449 | MED 5.5 | linux linux_kernel The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file. | 0.4% | — |
| CVE-2017-6773 | MED 6.7 | cisco asr_5000_software A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to bypass the CLI restrictions and execute commands on the underlying operating system. The v | 0.4% | — |
| CVE-2017-2584 | HIGH 7.1 | linux linux_kernel arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgd | 0.4% | — |
| CVE-2017-18270 | HIGH 7.1 | linux linux_kernel In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service. | 0.4% | — |
| CVE-2017-16650 | MED 6.6 | linux linux_kernel The qmi_wwan_bind function in drivers/net/usb/qmi_wwan.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.4% | — |
| CVE-2016-9196 | MED 6.7 | cisco aironet_access_point A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, local attacker to gain unrestricted root access to the underlying Linux operating system. The root Linux shell | 0.4% | — |
| CVE-2016-6414 | HIGH 7.8 | cisco ios iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223. | 0.4% | — |
| CVE-2011-1598 | MED 4.9 | linux linux_kernel The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a | 0.4% | — |
| CVE-2010-3698 | MED 4.9 | fedoraproject fedora The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor | 0.4% | — |
| CVE-2010-2942 | MED 5.5 | avaya aura_communication_manager The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information | 0.4% | — |
| CVE-2005-3271 | LOW 2.1 | linux linux_kernel Exec in Linux kernel 2.6 does not properly clear posix-timers in multi-threaded environments, which results in a resource leak and could allow a large number of multiple local users to cause a denial of service by using more posix-timers than specified by the | 0.4% | — |
| CVE-2004-1057 | HIGH 7.2 | linux linux_kernel Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages. | 0.4% | — |
| CVE-2026-77490 | MED 6.1 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-40401 | HIGH 7.1 | microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability | 0.4% | — |
| CVE-2025-67685 | LOW 3.8 | fortinet fortisandbox A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy in | 0.4% | — |
| CVE-2025-60004 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected | 0.4% | — |
| CVE-2025-29842 | HIGH 7.5 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2025-24049 | HIGH 8.4 | microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-13459 | LOW 2.7 | ibm aspera_console IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow. | 0.4% | — |
| CVE-2024-26801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPIO reset mechanism would | 0.4% | — |
| CVE-2024-0310 | MED 6.1 | trellix endpoint_security_web_control A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to byp | 0.4% | — |
| CVE-2023-51557 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0.4% | — |
| CVE-2023-51556 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0.4% | — |