IT
57.084 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.084 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2005-0210 MED 4.9 linux linux_kernel Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice. 0.4%
CVE-2026-61350 MED 4.6 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. 0.4%
CVE-2026-57817 HIGH 8.1 apache cxf The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the 0.4%
CVE-2026-55026 MED 6.2 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-47938 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. 0.4%
CVE-2026-44616 MED 6.5 apache zeppelin LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint                  0.4%
CVE-2026-31417 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging `fragment_queue` in `x2 0.4%
CVE-2026-30912 HIGH 7.5 apache airflow In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, wh 0.4%
CVE-2026-23242 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_dat 0.4%
CVE-2025-53726 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53724 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53152 HIGH 7.8 microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. 0.4%
CVE-2025-21360 HIGH 7.8 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.4%
CVE-2024-49864 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thread creation In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This is a problem, however 0.4%
CVE-2024-25709 MED 6.1 esri portal_for_arcgis There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could 0.4%
CVE-2023-41676 MED 4.3 fortinet fortisiem An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs. 0.4%
CVE-2023-20037 MED 5.4 cisco industrial_network_director A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An att 0.4%
CVE-2022-44699 MED 5.5 microsoft azure_network_watcher_agent Azure Network Watcher Agent Security Feature Bypass Vulnerability 0.4%
CVE-2022-38412 HIGH 7.8 adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu 0.4%
CVE-2022-34706 HIGH 7.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.4%
CVE-2022-23439 MED 4.7 fortinet fortiadc A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver 0.4%
CVE-2022-20787 MED 5.7 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request for 0.4%
CVE-2022-20742 HIGH 7.4 cisco adaptive_security_appliance_software A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerab 0.4%
CVE-2021-39090 MED 5.9 ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive 0.4%
CVE-2021-23175 HIGH 8.2 nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information d 0.4%