IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-1447 MED 5.4 microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445. 0.8%
CVE-2019-1445 MED 5.4 microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447. 0.8%
CVE-2019-12881 HIGH 7.8 linux linux_kernel i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl ca 0.8%
CVE-2026-64608 CRIT 9.8 apache fory Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent s 0.8%
CVE-2026-21523 HIGH 8.0 microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-25069 MED 6.5 apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi 0.8%
CVE-2024-43542 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43540 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43538 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43537 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2023-21749 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2022-41043 LOW 3.3 microsoft office Microsoft Office Information Disclosure Vulnerability 0.8%
CVE-2022-33631 HIGH 7.3 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0.8%
CVE-2022-29473 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminat 0.8%
CVE-2022-28706 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En 0.8%
CVE-2022-26517 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, undisclosed requests can 0.8%
CVE-2022-26370 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message 0.8%
CVE-2021-28309 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8%
CVE-2021-27093 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8%
CVE-2021-26417 MED 5.5 microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability 0.8%
CVE-2020-3267 HIGH 7.1 cisco unified_contact_center_express A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an aff 0.8%
CVE-2020-16922 MED 5.3 microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by 0.8%
CVE-2013-6698 MED 4.3 cisco wireless_lan_controller The web interface on Cisco Wireless LAN Controller (WLC) devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "c 0.8%
CVE-2026-8481 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() 0.8%
CVE-2026-69372 MED 5.7 microsoft windows_10_1607 Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. 0.8%