IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-48563 HIGH 7.5 microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-47654 HIGH 7.5 microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-46591 HIGH 8.2 apache camel Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-202 0.5% —
CVE-2026-46586 HIGH 8.8 apache ofbiz Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad 0.5% —
CVE-2026-45172 HIGH 8.8 paloaltonetworks idira_privileged_session_manager_for_ssh Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security B 0.5% —
CVE-2026-32169 CRIT 10.0 microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-31405 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elem 0.5% —
CVE-2026-20342 HIGH 7.7 A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker 0.5% —
CVE-2026-13476 HIGH 7.3 ibm informix_dynamic_server IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. 0.5% —
CVE-2024-30303 HIGH 7.8 adobe acrobat Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi 0.5% —
CVE-2023-40283 HIGH 7.8 canonical ubuntu_linux An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. 0.5% —
CVE-2023-20232 MED 5.3 cisco unified_contact_center_express A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input val 0.5% —
CVE-2022-41157 HIGH 8.1 webcash serp_server_2.0 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. 0.5% —
CVE-2022-22156 MED 6.5 juniper junos An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and 0.5% —
CVE-2022-22045 HIGH 7.8 microsoft windows_10 Windows.Devices.Picker.dll Elevation of Privilege Vulnerability 0.5% —
CVE-2021-38671 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5% —
CVE-2021-38667 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5% —
CVE-2021-3489 HIGH 7.8 canonical ubuntu_linux The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This is 0.5% —
CVE-2021-31973 HIGH 7.8 microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability 0.5% —
CVE-2021-31953 HIGH 7.8 microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability 0.5% —
CVE-2021-31190 HIGH 7.8 microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability 0.5% —
CVE-2021-28436 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5% —
CVE-2021-28351 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5% —
CVE-2021-28347 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5% —
CVE-2021-28320 HIGH 7.8 microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability 0.5% —