IT
57.725 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.725 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-67389 MED 6.5 microsoft sql_server_2022 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-64269 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE th 0.7%
CVE-2026-64268 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->proc 0.7%
CVE-2024-43460 HIGH 8.1 microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. 0.7%
CVE-2024-26782 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same 0.7%
CVE-2023-35625 MED 4.7 microsoft azure_machine_learning_software_development_kit Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability 0.7%
CVE-2022-41733 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. IBM X-Force ID: 237583. 0.7%
CVE-2022-22717 HIGH 7.0 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7%
CVE-2021-38979 HIGH 7.5 ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785. 0.7%
CVE-2021-20410 MED 5.3 ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190. 0.7%
CVE-2021-1680 HIGH 7.8 microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability 0.7%
CVE-2020-7811 MED 6.2 samsung update Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication 0.7%
CVE-2017-3128 MED 4.8 fortinet fortios A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter. 0.7%
CVE-2010-3699 LOW 2.7 citrix xen The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands fro 0.7%
CVE-2026-29145 CRIT 9.1 apache tomcat CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0 0.7%
CVE-2024-45324 HIGH 7.2 fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b 0.7%
CVE-2024-28920 HIGH 7.8 microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-26582 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, an 0.7%
CVE-2024-20458 HIGH 8.2 cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerabil 0.7%
CVE-2023-6931 HIGH 7.8 debian debian_linux A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_rea 0.7%
CVE-2023-36898 HIGH 7.8 microsoft windows_11_21h2 Tablet Windows User Interface Application Core Remote Code Execution Vulnerability 0.7%
CVE-2023-31488 CRIT 9.8 cisco ironport_email_security_appliance Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbit 0.7%
CVE-2022-24466 MED 4.1 microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability 0.7%
CVE-2020-0785 HIGH 7.1 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2017-12281 HIGH 7.5 cisco aironet_1800_firmware A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass auth 0.7%