58.449 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.449 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-5525 | HIGH 8.8 | vmware workstation VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues t | 0.4% | — |
| CVE-2017-17862 | MED 5.5 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial | 0.4% | — |
| CVE-2017-17807 | LOW 3.3 | linux linux_kernel The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add | 0.4% | — |
| CVE-2017-12137 | HIGH 8.8 | citrix xenserver arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref. | 0.4% | — |
| CVE-2016-9576 | HIGH 7.8 | linux linux_kernel The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) | 0.4% | — |
| CVE-2015-7884 | LOW 2.3 | linux linux_kernel The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application. | 0.4% | — |
| CVE-2012-3498 | MED 5.6 | citrix xenserver PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index. | 0.4% | — |
| CVE-2012-3494 | LOW 2.1 | citrix xenserver The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of | 0.4% | — |
| CVE-2012-1509 | HIGH 7.2 | vmware view Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors. | 0.4% | — |
| CVE-2011-1759 | MED 6.2 | linux linux_kernel Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory | 0.4% | — |
| CVE-2005-3356 | LOW 2.1 | linux linux_kernel The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice ("double decrement") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial o | 0.4% | — |
| CVE-2005-1762 | LOW 2.1 | linux linux_kernel The ptrace call in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform allows local users to cause a denial of service (kernel crash) via a "non-canonical" address. | 0.4% | — |
| CVE-2005-0756 | LOW 2.1 | linux linux_kernel ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash). | 0.4% | — |
| CVE-2005-0135 | LOW 2.1 | linux linux_kernel The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash). | 0.4% | — |
| CVE-2026-78451 | MED 6.8 | microsoft windows_10_1809 Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-77892 | MED 6.8 | microsoft windows_10_1607 No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-72999 | MED 6.8 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-72985 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-69490 | MED 6.8 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-54132 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-50668 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-50492 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50299 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50298 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-49168 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |