58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-8429 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2016-8428 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2016-8427 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2016-8426 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2016-8425 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2016-8424 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromis | 1.6% | — |
| CVE-2009-1165 | HIGH 7.8 | cisco catalyst_3750g Memory leak on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0, 5.1 before 5.1.163.0, and 5.0 and 5.2 before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Mo | 1.6% | — |
| CVE-2009-1163 | HIGH 7.8 | cisco physical_access_gateway Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets. | 1.6% | — |
| CVE-2009-0061 | HIGH 7.8 | cisco 4400_wireless_lan_controller Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5. | 1.6% | — |
| CVE-2007-3350 | HIGH 7.8 | aol instant_messenger AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP INVITE requests. | 1.6% | — |
| CVE-2007-1981 | HIGH 7.8 | metamod-p metamod-p The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command. | 1.6% | — |
| CVE-2006-4032 | MED 5.0 | cisco callmanager_express Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417. | 1.6% | — |
| CVE-2002-0241 | HIGH 7.5 | cisco secure_access_control_server NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server. | 1.6% | — |
| CVE-2024-38127 | HIGH 7.8 | microsoft windows_10_1507 Windows Hyper-V Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2020-3500 | MED 6.8 | cisco staros A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An atta | 1.6% | — |
| CVE-2020-15604 | HIGH 7.5 | trendmicro antivirus\+_2019 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a maliciou | 1.6% | — |
| CVE-2019-1283 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2016-1364 | HIGH 7.5 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908. | 1.6% | — |
| CVE-2014-9940 | HIGH 7.0 | google android The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application. | 1.6% | — |
| CVE-2013-6964 | LOW 3.5 | cisco webex_meeting_center Cisco WebEx Meeting Center allows remote authenticated users to bypass access control and inject content from a different WebEx site via unspecified vectors, aka Bug ID CSCul36197. | 1.6% | — |
| CVE-2012-1038 | MED 4.3 | juniper networks_mobility_system_software Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows | 1.6% | — |
| CVE-2011-4856 | HIGH 9.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/para | 1.6% | — |
| CVE-2011-4855 | HIGH 9.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admi | 1.6% | — |
| CVE-2011-4854 | HIGH 9.3 | parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an | 1.6% | — |
| CVE-2024-49068 | HIGH 8.2 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 1.6% | — |