IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2002-0225 MED 4.6 cisco tacacs\+ tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files. 0.3%
CVE-2026-78222 HIGH 7.5 A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: 0.3%
CVE-2026-64235 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform (eg: Skylake), with retbleed=stuff, registe 0.3%
CVE-2026-59654 HIGH 7.5 apache cloudstack Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to e 0.3%
CVE-2026-58177 HIGH 8.1 apache traffic_server The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. 0.3%
CVE-2026-54665 MED 5.3 apache nifi Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application pro 0.3%
CVE-2026-23139 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when GC has been performed Currently last_gc is being updated everytime a new connection is tracked, that means that it is updated even if a GC w 0.3%
CVE-2025-62569 HIGH 7.0 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-61935 HIGH 7.5 f5 big-ip_advanced_web_application_firewall When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.3%
CVE-2025-60717 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59515 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59504 HIGH 7.3 microsoft azure_monitor_agent Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58738 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58736 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58734 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58733 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58731 HIGH 7.0 microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-58730 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-20216 MED 4.7 cisco catalyst_sd-wan_manager A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitizatio 0.3%
CVE-2025-14974 MED 5.7 ibm infosphere_information_server IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR). 0.3%
CVE-2025-13726 MED 5.3 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks aga 0.3%
CVE-2024-8035 MED 4.3 google chrome Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) 0.3%
CVE-2024-56651 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr eve 0.3%
CVE-2024-50001 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping f 0.3%
CVE-2024-49894 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could 0.3%