57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-83941 | CRIT 9.9 | microsoft entra_id Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-26083 | CRIT 9.8 | fortinet fortisandbox A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all v | 0.7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-52067 | MED 4.9 | apache nifi Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for | 0.7% | — |
| CVE-2024-42152 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin con | 0.7% | — |
| CVE-2024-36916 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behav | 0.7% | — |
| CVE-2024-28903 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-24779 | MED 5.0 | apache superset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to una | 0.7% | — |
| CVE-2023-34984 | HIGH 7.5 | fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | 0.7% | — |
| CVE-2021-20444 | MED 6.1 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr | 0.7% | — |
| CVE-2021-0297 | MED 6.5 | juniper junos_os_evolved A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to unt | 0.7% | — |
| CVE-2020-1312 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2020-1302 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2020-1277 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2017-2218 | HIGH 7.8 | apple quicktime Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 0.7% | — |
| CVE-2010-3411 | MED 5.0 | google chrome Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors. | 0.7% | — |
| CVE-2026-53176 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus | 0.7% | — |
| CVE-2026-48204 | CRIT 9.8 | apache camel Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operati | 0.7% | — |
| CVE-2026-47644 | MED 6.5 | microsoft copilot_chat Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-43975 | MED 6.5 | apache wicket FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or r | 0.7% | — |
| CVE-2025-21257 | MED 5.5 | microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-43626 | HIGH 7.8 | microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30041 | MED 5.4 | microsoft bing_search Microsoft Bing Search Spoofing Vulnerability | 0.7% | — |
| CVE-2023-27727 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | 0.7% | — |
| CVE-2022-33875 | MED 5.4 | fortinet fortiadc An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or c | 0.7% | — |