IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-23395 LOW 3.1 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 0.6%
CVE-2021-27072 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2019-1846 HIGH 7.4 cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr 0.6%
CVE-2019-1749 HIGH 7.4 cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in 0.6%
CVE-2018-11760 MED 5.5 apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. 0.6%
CVE-2026-78519 HIGH 8.8 microsoft 365_apps Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-69297 MED 6.5 microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-68823 CRIT 9.1 microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 0.6%
CVE-2026-50525 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2025-59234 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-39688 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then 0.6%
CVE-2025-21403 MED 6.4 microsoft on-prem_data_gateway On-Premises Data Gateway Information Disclosure Vulnerability 0.6%
CVE-2025-21304 HIGH 7.8 microsoft windows_10_1607 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.6%
CVE-2024-43527 HIGH 7.8 microsoft windows_11_24h2 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2024-43514 HIGH 7.8 microsoft windows_10_1507 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.6%
CVE-2024-38253 HIGH 7.8 microsoft windows_11_21h2 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.6%
CVE-2024-38252 HIGH 7.8 microsoft windows_10_1607 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.6%
CVE-2023-20116 MED 6.8 cisco unified_communications_manager A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a d 0.6%
CVE-2022-26921 HIGH 7.3 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.6%
CVE-2021-22979 MED 6.1 f5 big-ip_access_policy_manager On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when F 0.6%
CVE-2020-9290 HIGH 7.8 fortinet forticlient An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrar 0.6%
CVE-2014-6385 MED 6.1 juniper junos Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.3R8, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1 0.6%
CVE-2004-2343 HIGH 7.2 apache http_server Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess 0.6%
CVE-2026-70340 HIGH 8.1 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-42440 HIGH 7.5 apache opennlp OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates 0.6%