IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-83941 CRIT 9.9 microsoft entra_id Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-26083 CRIT 9.8 fortinet fortisandbox A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all v 0.7%
CVE-2025-49746 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2024-52067 MED 4.9 apache nifi Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for 0.7%
CVE-2024-42152 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin con 0.7%
CVE-2024-36916 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behav 0.7%
CVE-2024-28903 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-24779 MED 5.0 apache superset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to una 0.7%
CVE-2023-34984 HIGH 7.5 fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. 0.7%
CVE-2021-20444 MED 6.1 ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr 0.7%
CVE-2021-0297 MED 6.5 juniper junos_os_evolved A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to unt 0.7%
CVE-2020-1312 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 0.7%
CVE-2020-1302 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 0.7%
CVE-2020-1277 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 0.7%
CVE-2017-2218 HIGH 7.8 apple quicktime Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 0.7%
CVE-2010-3411 MED 5.0 google chrome Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors. 0.7%
CVE-2026-53176 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus 0.7%
CVE-2026-48204 CRIT 9.8 apache camel Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operati 0.7%
CVE-2026-47644 MED 6.5 microsoft copilot_chat Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-43975 MED 6.5 apache wicket FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or r 0.7%
CVE-2025-21257 MED 5.5 microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability 0.7%
CVE-2024-43626 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability 0.7%
CVE-2024-30041 MED 5.4 microsoft bing_search Microsoft Bing Search Spoofing Vulnerability 0.7%
CVE-2023-27727 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. 0.7%
CVE-2022-33875 MED 5.4 fortinet fortiadc An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or c 0.7%