IT
57.484 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.484 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2025-27427 MED 4.3 apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo 0.6%
CVE-2025-26674 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2025-26666 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2024-50215 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after 0.6%
CVE-2024-40587 MED 6.7 fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or 0.6%
CVE-2024-38122 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0.6%
CVE-2024-38118 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0.6%
CVE-2022-23015 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processin 0.6%
CVE-2021-32584 MED 5.3 fortinet fortiwlc An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain ar 0.6%
CVE-2021-31354 HIGH 7.1 juniper junos An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause 0.6%
CVE-2016-6427 HIGH 8.8 cisco unified_contact_center_express Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bu 0.6%
CVE-2016-6417 HIGH 8.8 cisco firesight_system_software Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. 0.6%
CVE-2026-62870 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-53229 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame() returns false (e.g. XDPSQ is full), the function retur 0.6%
CVE-2026-53198 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A deferred byte-range lock (an SMB2_LOCK that blocks) registers an async work on conn->async_requests via setup_async_ 0.6%
CVE-2026-49434 HIGH 7.5 apache activemq Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports i 0.6%
CVE-2026-46585 HIGH 7.5 apache camel Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain stri 0.6%
CVE-2026-40371 HIGH 8.8 microsoft dynamics_365 Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-33558 MED 5.3 apache kafka Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is 0.6%
CVE-2026-25186 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally. 0.6%
CVE-2026-24735 HIGH 7.5 apache answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unau 0.6%
CVE-2025-57740 HIGH 7.5 fortinet fortios An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions 0.6%
CVE-2024-30405 HIGH 7.5 juniper junos An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Con 0.6%
CVE-2024-20433 HIGH 8.6 cisco ios A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condi 0.6%
CVE-2023-47540 MED 6.7 fortinet fortisandbox An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandb 0.6%