IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-66713 CRIT 9.8 apache axis2\/java Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthentic 1.0%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2024-49088 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.0%
CVE-2024-26248 HIGH 7.5 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.0%
CVE-2023-36730 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 1.0%
CVE-2023-35348 MED 6.5 microsoft windows_server_2016 Active Directory Federation Service Security Feature Bypass Vulnerability 1.0%
CVE-2021-34691 HIGH 7.5 idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. 1.0%
CVE-2017-10608 HIGH 7.5 juniper junos Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated d 1.0%
CVE-2017-10607 HIGH 7.5 juniper junos Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, 1.0%
CVE-2026-21218 HIGH 7.5 microsoft .net Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2023-38741 HIGH 7.5 ibm txseries_for_multiplatform IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to 1.0%
CVE-2023-36881 MED 4.5 microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability 1.0%
CVE-2023-36877 MED 4.5 microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability 1.0%
CVE-2022-22183 HIGH 7.5 juniper junos_os_evolved An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to c 1.0%
CVE-2020-2050 HIGH 8.2 paloaltonetworks pan-os An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authentic 1.0%
CVE-2020-19725 HIGH 7.8 microsoft z3 There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution. 1.0%
CVE-2020-0911 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit t 1.0%
CVE-2016-8478 MED 4.7 linux linux_kernel An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc 1.0%
CVE-2016-8416 MED 4.7 linux linux_kernel An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc 1.0%
CVE-2014-3399 MED 5.5 cisco adaptive_security_appliance_software The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cach 1.0%
CVE-2013-3888 HIGH 8.4 microsoft windows_7 dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability." 1.0%
CVE-2009-4804 MED 4.3 mario_matzulla calendar_base Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via "search parameters." 1.0%
CVE-2008-6096 MED 4.3 juniper netscreen_screenos Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page. 1.0%
CVE-2008-1503 MED 4.3 f5 tmos Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a node object, or the (2) sysContact or (3) sysLocation SNMP configuration field, aka 1.0%
CVE-2025-64678 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.0%