IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-40948 MED 5.4 apache apache-airflow-providers-keycloak The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could delive 0.4% —
CVE-2026-3544 HIGH 8.8 google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-21743 HIGH 7.2 fortinet fortiauthenticator A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local use 0.4% —
CVE-2026-20286 MED 4.3 A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side vali 0.4% —
CVE-2026-20285 MED 4.3 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This v 0.4% —
CVE-2025-55230 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53789 HIGH 7.8 microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53782 HIGH 8.4 microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53721 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53140 HIGH 7.0 microsoft windows_10_1507 Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-53133 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-50167 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-39770 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel inco 0.4% —
CVE-2025-3940 MED 5.3 tridium niagara Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15. 0.4% —
CVE-2025-37952 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks o 0.4% —
CVE-2025-20285 MED 4.1 cisco identity_services_engine A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to 0.4% —
CVE-2025-0104 MED 6.1 paloaltonetworks expedition A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that al 0.4% —
CVE-2024-45654 MED 4.3 ibm security_qradar_edr IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. 0.4% —
CVE-2023-21584 MED 5.5 adobe framemaker FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this 0.4% —
CVE-2022-50386 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap 0.4% —
CVE-2022-49928 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix null-ptr-deref when xps sysfs alloc failed There is a null-ptr-deref when xps sysfs alloc failed: BUG: KASAN: null-ptr-deref in sysfs_do_create_link_sd+0x40/0xd0 Read of size 0.4% —
CVE-2022-49114 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix use after free in fc_exch_abts_resp() fc_exch_release(ep) will decrease the ep's reference count. When the reference count reaches zero, it is freed. But ep is still used in 0.4% —
CVE-2022-24505 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.4% —
CVE-2021-34729 MED 6.7 cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation 0.4% —
CVE-2021-34725 MED 6.7 cisco ios_xe_sd-wan A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input v 0.4% —