IT
57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-25180 MED 5.5 microsoft 365_copilot Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. 0.7%
CVE-2026-24212 HIGH 7.5 nvidia isaac_launchable NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. 0.7%
CVE-2025-68438 HIGH 7.5 apache airflow In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a se 0.7%
CVE-2025-66335 MED 5.3 apache doris_mcp_server Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP 0.7%
CVE-2025-48795 MED 5.6 apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic 0.7%
CVE-2024-43501 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-38612 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist 0.7%
CVE-2024-29061 HIGH 7.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2023-32037 MED 6.5 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability 0.7%
CVE-2022-49260 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as settin 0.7%
CVE-2020-8428 HIGH 7.1 linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope 0.7%
CVE-2026-50485 MED 4.5 microsoft windows_10_1607 Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. 0.7%
CVE-2025-49689 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. 0.7%
CVE-2025-27531 CRIT 9.8 apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended t 0.7%
CVE-2024-37304 MED 6.1 microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately 0.7%
CVE-2024-30363 MED 5.5 foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this 0.7%
CVE-2024-26953 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: esp: fix bad handling of pages from page_pool When the skb is reorganized during esp_output (!esp->inline), the pages coming from the original skb fragments are supposed to be released 0.7%
CVE-2023-2313 HIGH 8.8 google chrome Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) 0.7%
CVE-2023-20192 CRIT 9.6 cisco telepresence_video_communication_server Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write creden 0.7%
CVE-2022-41334 HIGH 8.8 fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of 0.7%
CVE-2022-35728 HIGH 8.1 f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain v 0.7%
CVE-2022-21928 MED 6.3 microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2022-21868 HIGH 7.0 microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability 0.7%
CVE-2021-43880 MED 5.5 microsoft windows_11 Windows Mobile Device Management Elevation of Privilege Vulnerability 0.7%
CVE-2026-50223 HIGH 8.8 apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi 0.7%