IT
58.434 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.434 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-58300 MED 6.2 microsoft edge_chromium Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-55045 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-47288 HIGH 7.1 microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. 0.4% —
CVE-2026-45458 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-45456 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-40367 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2026-23902 HIGH 8.1 apache dolphinscheduler Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior 0.4% —
CVE-2026-20329 CRIT 9.9 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond 0.4% —
CVE-2026-20194 CRIT 9.1 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review 0.4% —
CVE-2025-43574 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i 0.4% —
CVE-2025-43573 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i 0.4% —
CVE-2025-20376 MED 6.5 cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exp 0.4% —
CVE-2024-56717 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix incorrect IFH SRC_PORT field in ocelot_ifh_set_basic() Packets injected by the CPU should have a SRC_PORT field equal to the CPU port module index in the Analyzer bloc 0.4% —
CVE-2024-50568 MED 5.9 fortinet fortios A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attack 0.4% —
CVE-2024-49046 HIGH 7.8 microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.4% —
CVE-2024-40910 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount imbalance on inbound connections When releasing a socket in ax25_release(), we call netdev_put() to decrease the refcount on the associated ax.25 device. However, the exec 0.4% —
CVE-2024-33506 LOW 3.3 fortinet fortimanager An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary 0.4% —
CVE-2023-20205 MED 5.4 cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a use 0.4% —
CVE-2023-20204 MED 5.4 cisco broadworks_application_delivery_platform A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists 0.4% —
CVE-2023-20203 MED 5.4 cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a use 0.4% —
CVE-2023-20132 MED 5.4 cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, 0.4% —
CVE-2022-2991 MED 6.7 linux linux_kernel A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local 0.4% —
CVE-2022-20945 HIGH 7.4 cisco catalyst_9800-40_firmware A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu 0.4% —
CVE-2021-1584 MED 6.0 cisco nx-os A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during 0.4% —
CVE-2019-19054 MED 4.7 broadcom brocade_fabric_operating_system_firmware A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b. 0.4% —