58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0368 | LOW 2.1 | cisco ios Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. | 0.4% | — |
| CVE-2026-69832 | MED 5.6 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59130 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50656 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | 0.4% | — |
| CVE-2026-31923 | HIGH 7.5 | apache apisix Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are reco | 0.4% | — |
| CVE-2026-29129 | HIGH 7.5 | apache tomcat Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, | 0.4% | — |
| CVE-2026-15371 | HIGH 8.1 | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScri | 0.4% | — |
| CVE-2025-59478 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support ( | 0.4% | — |
| CVE-2025-55322 | HIGH 7.3 | microsoft omniparser Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2025-55316 | HIGH 7.8 | microsoft azure_connected_machine_agent External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-24036 | HIGH 7.0 | microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-21160 | HIGH 7.8 | adobe illustrator Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.4% | — |
| CVE-2025-1992 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after us | 0.4% | — |
| CVE-2024-41857 | HIGH 7.8 | adobe illustrator Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.4% | — |
| CVE-2024-35265 | HIGH 7.0 | microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-34121 | HIGH 7.8 | adobe illustrator Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi | 0.4% | — |
| CVE-2024-2049 | MED 6.5 | citrix sd-wan_1000_firmware Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP. | 0.4% | — |
| CVE-2024-0134 | MED 4.1 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker | 0.4% | — |
| CVE-2023-52624 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang. [How] A | 0.4% | — |
| CVE-2023-28529 | MED 5.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0.4% | — |
| CVE-2023-20106 | MED 5.4 | cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affecte | 0.4% | — |
| CVE-2023-1003 | MED 5.3 | typora typora A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit h | 0.4% | — |
| CVE-2022-22176 | HIGH 7.4 | juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial | 0.4% | — |
| CVE-2022-22163 | HIGH 7.4 | juniper junos An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If a device is configured as DHCPv6 local | 0.4% | — |
| CVE-2021-45486 | LOW 3.5 | linux linux_kernel In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small. | 0.4% | — |