IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2000-0368 LOW 2.1 cisco ios Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. 0.4% —
CVE-2026-69832 MED 5.6 microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-59130 MED 5.6 microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-50656 HIGH 7.8 microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". 0.4% —
CVE-2026-31923 HIGH 7.5 apache apisix Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are reco 0.4% —
CVE-2026-29129 HIGH 7.5 apache tomcat Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 0.4% —
CVE-2026-15371 HIGH 8.1 Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScri 0.4% —
CVE-2025-59478 HIGH 7.5 f5 big-ip_advanced_firewall_manager When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support ( 0.4% —
CVE-2025-55322 HIGH 7.3 microsoft omniparser Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. 0.4% —
CVE-2025-55316 HIGH 7.8 microsoft azure_connected_machine_agent External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-24036 HIGH 7.0 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.4% —
CVE-2025-21160 HIGH 7.8 adobe illustrator Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that 0.4% —
CVE-2025-1992 MED 5.3 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after us 0.4% —
CVE-2024-41857 HIGH 7.8 adobe illustrator Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that 0.4% —
CVE-2024-35265 HIGH 7.0 microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability 0.4% —
CVE-2024-34121 HIGH 7.8 adobe illustrator Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi 0.4% —
CVE-2024-2049 MED 6.5 citrix sd-wan_1000_firmware Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP. 0.4% —
CVE-2024-0134 MED 4.1 nvidia nvidia_container_toolkit NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker 0.4% —
CVE-2023-52624 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang. [How] A 0.4% —
CVE-2023-28529 MED 5.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within 0.4% —
CVE-2023-20106 MED 5.4 cisco identity_services_engine Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affecte 0.4% —
CVE-2023-1003 MED 5.3 typora typora A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit h 0.4% —
CVE-2022-22176 HIGH 7.4 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial 0.4% —
CVE-2022-22163 HIGH 7.4 juniper junos An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If a device is configured as DHCPv6 local 0.4% —
CVE-2021-45486 LOW 3.5 linux linux_kernel In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small. 0.4% —