IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2012-2847 MED 4.3 google chrome Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of ser 0.8%
CVE-2026-40021 MED 5.3 apache log4net Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitiz 0.8%
CVE-2026-25903 MED 6.6 apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi 0.8%
CVE-2026-20834 MED 4.6 microsoft windows_10_1607 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. 0.8%
CVE-2024-49044 MED 6.7 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.8%
CVE-2024-38166 HIGH 8.2 microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. 0.8%
CVE-2024-36471 HIGH 7.5 apache allura Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allur 0.8%
CVE-2024-36288 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory 0.8%
CVE-2023-32051 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.8%
CVE-2023-20030 MED 6.0 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or nega 0.8%
CVE-2022-28716 HIGH 7.5 f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o 0.8%
CVE-2022-22415 MED 6.5 ibm robotic_process_automation A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. 0.8%
CVE-2021-43246 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2021-24023 HIGH 7.8 fortinet fortiai_firmware An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command. 0.8%
CVE-2009-0746 MED 4.9 linux linux_kernel The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext 0.8%
CVE-1999-0720 MED 4.6 linux linux_kernel The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users. 0.8%
CVE-2026-70306 CRIT 9.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2026-45249 MED 6.1 apache echarts A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-speci 0.7%
CVE-2026-0227 HIGH 7.5 paloaltonetworks pan-os A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. 0.7%
CVE-2025-62222 HIGH 8.8 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-46548 MED 6.5 akka akka_management If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to 0.7%
CVE-2025-21416 HIGH 8.5 microsoft azure_virtual_desktop Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2024-40761 MED 5.3 apache answer Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to 0.7%
CVE-2023-23420 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2021-34744 MED 4.9 cisco business_220-16p-2g_firmware Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnera 0.7%