57.061 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-68968 | HIGH 7.5 | apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative | 0.4% | — |
| CVE-2026-58186 | HIGH 7.5 | apache traffic_server The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | 0.4% | — |
| CVE-2026-32181 | MED 5.5 | microsoft windows_10_21h2 Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-31388 | MED 5.3 | apache ofbiz Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.4% | — |
| CVE-2026-26178 | HIGH 8.8 | microsoft windows_10_1607 Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-26109 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-24162 | HIGH 7.8 | nvidia transformers4rec NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | 0.4% | — |
| CVE-2026-22573 | MED 6.5 | fortinet fortisoar An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-prem | 0.4% | — |
| CVE-2025-66723 | HIGH 7.5 | inmusicbrands engine_dj_desktop inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | 0.4% | — |
| CVE-2024-51476 | HIGH 7.5 | ibm concert_software IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | 0.4% | — |
| CVE-2024-46697 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to checking for the security label, then args.context will be set to | 0.4% | — |
| CVE-2024-43856 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma: fix call order in dmam_free_coherent dmam_free_coherent() frees a DMA allocation, which makes the freed vaddr available for reuse, then calls devres_destroy() to remove and free the dat | 0.4% | — |
| CVE-2024-27404 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data races on remote_id Similar to the previous patch, address the data race on remote_id, adding the suitable ONCE annotations. | 0.4% | — |
| CVE-2024-20465 | MED 5.8 | cisco ios A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is du | 0.4% | — |
| CVE-2022-3545 | MED 5.5 | debian debian_linux A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use | 0.4% | — |
| CVE-2022-35285 | HIGH 8.8 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. | 0.4% | — |
| CVE-2022-0494 | MED 4.4 | debian debian_linux A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality. | 0.4% | — |
| CVE-2021-47097 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in elantech_change_report_id() The array param[] in elantech_change_report_id() must be at least 3 bytes, because elantech_read_reg_params() i | 0.4% | — |
| CVE-2021-45402 | MED 5.5 | linux linux_kernel The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak." | 0.4% | — |
| CVE-2021-1354 | MED 4.3 | cisco unified_computing_system_central_software A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM). This vulnerability is due to imp | 0.4% | — |
| CVE-2020-8992 | MED 5.5 | canonical ubuntu_linux ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. | 0.4% | — |
| CVE-2020-3420 | MED 5.4 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-sit | 0.4% | — |
| CVE-2020-14385 | MED 5.5 | canonical ubuntu_linux A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwis | 0.4% | — |
| CVE-2017-12223 | MED 6.4 | cisco ir800_integrated_services_router_firmware A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerabilit | 0.4% | — |
| CVE-2015-9289 | MED 5.5 | linux linux_kernel In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23. | 0.4% | — |