IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-63046 HIGH 8.8 apache inlong Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issu 0.4%
CVE-2026-58542 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-58530 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-50501 HIGH 7.8 microsoft windows_11_24h2 Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-50498 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4%
CVE-2026-41614 MED 6.2 microsoft 365_copilot Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. 0.4%
CVE-2025-64673 HIGH 7.8 microsoft windows_10_1809 Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-52447 HIGH 8.1 tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Se 0.4%
CVE-2025-27555 MED 6.5 apache airflow Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables 0.4%
CVE-2025-27475 HIGH 7.0 microsoft windows_11_22h2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-23339 LOW 3.3 nvidia cuda_toolkit NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary 0.4%
CVE-2025-22110 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error It is possible that ctx in nfqnl_build_packet_message() could be used before it is properly initialize, which is o 0.4%
CVE-2025-0589 MED 5.3 octopus octopus_server In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. T 0.4%
CVE-2024-45323 MED 4.3 fortinet fortiedrmanager An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization 0.4%
CVE-2024-41840 HIGH 7.8 adobe bridge Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 0.4%
CVE-2024-30410 MED 5.8 juniper junos An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interface. The intended functio 0.4%
CVE-2024-30389 MED 5.8 juniper junos An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device. When 0.4%
CVE-2023-36405 HIGH 7.0 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2023-2873 MED 5.3 filseclab twister_antivirus A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to memory corr 0.4%
CVE-2023-2006 HIGH 7.0 linux linux_kernel A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and e 0.4%
CVE-2022-20662 MED 6.1 cisco duo A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched wit 0.4%
CVE-2021-27194 HIGH 8.8 netop vision_pro Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. 0.4%
CVE-2020-26155 HIGH 7.8 utimaco block-safe_firmware Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH en 0.4%
CVE-2020-1618 MED 6.3 juniper junos On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot after performing device 0.4%
CVE-2019-1966 HIGH 7.8 cisco nx-os A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerabi 0.4%