IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-3206 MED 4.7 cisco ios_xe A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to terminate a valid user connection 0.5% —
CVE-2020-10766 MED 5.5 linux linux_kernel A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations ar 0.5% —
CVE-2019-17654 HIGH 8.8 fortinet fortimanager An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack. 0.5% —
CVE-2018-20855 LOW 3.3 linux linux_kernel An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace. 0.5% —
CVE-2018-20511 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via 0.5% —
CVE-2018-1780 HIGH 7.8 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permiss 0.5% —
CVE-2011-4110 LOW 2.1 linux linux_kernel The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully inst 0.5% —
CVE-2010-2803 LOW 1.9 debian debian_linux The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially 0.5% —
CVE-2004-0010 HIGH 7.2 linux linux_kernel Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges. 0.5% —
CVE-2026-78508 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-78452 MED 4.6 microsoft windows_10_1809 Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-69548 MED 4.6 microsoft windows_10_1607 Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-69381 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-66842 HIGH 8.8 BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacke 0.5% —
CVE-2026-61350 MED 4.6 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-49794 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-47898 CRIT 9.8 apache lucene.net Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade 0.5% —
CVE-2026-45655 MED 5.3 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5% —
CVE-2026-26175 MED 4.6 microsoft windows_10_1607 Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5% —
CVE-2026-13020 HIGH 8.1 esri portal_for_arcgis A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcG 0.5% —
CVE-2025-62449 MED 6.8 microsoft github_copilot_chat Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. 0.5% —
CVE-2024-28905 HIGH 7.8 microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.5% —
CVE-2024-20469 MED 6.0 cisco identity_services_engine A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, 0.5% —
CVE-2023-5345 HIGH 7.8 fedoraproject fedora A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead 0.5% —
CVE-2023-4550 HIGH 7.5 opentext appbuilder Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on 0.5% —