IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-47023 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there might be a crash during ports creation if port events are handling at the same time because fw may send initial 0.8%
CVE-2021-1481 MED 4.3 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input 0.8%
CVE-2020-6643 MED 5.4 fortinet fortiisolator An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS). 0.8%
CVE-2020-3579 MED 6.1 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-base 0.8%
CVE-2020-3137 MED 6.1 cisco email_security_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev 0.8%
CVE-2020-3136 MED 6.1 cisco jabber_guest A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabi 0.8%
CVE-2020-16993 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.8%
CVE-2018-21033 MED 6.5 hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token se 0.8%
CVE-2011-2481 MED 4.6 apache tomcat Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted appli 0.8%
CVE-2026-9135 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur 0.8%
CVE-2026-69507 MED 5.7 microsoft windows_11_23h2 Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-69349 MED 5.7 microsoft windows_10_1607 Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-68874 MED 5.7 microsoft windows_10_1607 Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-24307 CRIT 9.3 microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2025-12763 MED 6.8 pgadmin pgadmin_4 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing speciall 0.8%
CVE-2024-30065 MED 5.5 microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability 0.8%
CVE-2024-20693 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2023-33146 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.8%
CVE-2023-30268 CRIT 9.8 cltphp cltphp CLTPHP <=6.0 is vulnerable to Improper Input Validation. 0.8%
CVE-2022-20786 MED 5.4 cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerabili 0.8%
CVE-2018-5803 MED 5.5 debian debian_linux In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash. 0.8%
CVE-2018-0215 MED 6.3 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera 0.8%
CVE-2017-8561 HIGH 7.0 microsoft windows_10 Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Ke 0.8%
CVE-2017-6794 MED 6.7 cisco meeting_server A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administ 0.8%
CVE-2026-41094 HIGH 8.8 microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. 0.8%