57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-42302 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-38874 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397. | 0.7% | — |
| CVE-2021-26880 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26872 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26870 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-15216 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver. | 0.7% | — |
| CVE-2016-6325 | HIGH 7.8 | apache tomcat The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership i | 0.7% | — |
| CVE-2026-81383 | HIGH 7.4 | microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80091 | MED 6.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80090 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80087 | MED 6.5 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80086 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80084 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80082 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80078 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-80076 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-78522 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-78502 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-77911 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-72975 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-49042 | HIGH 7.3 | apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue. | 0.7% | — |
| CVE-2026-46588 | HIGH 7.3 | apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue. | 0.7% | — |
| CVE-2026-46587 | HIGH 7.3 | apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue. | 0.7% | — |
| CVE-2026-34176 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End | 0.7% | — |
| CVE-2026-33791 | MED 6.7 | juniper junos An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete co | 0.7% | — |