IT
57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.918 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2018-10878 HIGH 7.8 canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. 0.8%
CVE-2017-5646 MED 6.8 apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a 0.8%
CVE-2026-49169 HIGH 8.0 microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. 0.8%
CVE-2026-47643 CRIT 9.8 microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-24098 MED 6.5 apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later 0.8%
CVE-2024-44940 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is 0.8%
CVE-2024-20451 HIGH 7.5 cisco spa_301_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. 0.8%
CVE-2023-41677 HIGH 7.5 fortinet fortios A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0 0.8%
CVE-2023-35389 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 0.8%
CVE-2026-65637 CRIT 9.8 apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrad 0.8%
CVE-2023-48362 HIGH 8.8 apache drill XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue. 0.8%
CVE-2023-36428 MED 5.5 microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability 0.8%
CVE-2023-36406 MED 5.5 microsoft windows_11_21h2 Windows Hyper-V Information Disclosure Vulnerability 0.8%
CVE-2023-28240 HIGH 8.8 microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability 0.8%
CVE-2022-37424 MED 6.5 opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. 0.8%
CVE-2020-0854 HIGH 7.1 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. 0.8%
CVE-2019-19927 MED 6.0 linux linux_kernel In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c 0.8%
CVE-2018-9186 MED 6.1 fortinet fortiauthenticator A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. 0.8%
CVE-2025-21363 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 0.8%
CVE-2024-28902 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-26255 MED 5.5 microsoft windows_10_1809 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-26207 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2024-20444 MED 5.5 cisco nexus_dashboard_fabric_controller A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. 0.8%
CVE-2023-36398 MED 6.5 microsoft windows_10_1507 Windows NTFS Information Disclosure Vulnerability 0.8%
CVE-2022-40732 MED 5.0 microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte 0.8%