57.084 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.084 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-0210 | MED 4.9 | linux linux_kernel Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice. | 0.4% | — |
| CVE-2026-61350 | MED 4.6 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | 0.4% | — |
| CVE-2026-57817 | HIGH 8.1 | apache cxf The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the | 0.4% | — |
| CVE-2026-55026 | MED 6.2 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-47938 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | 0.4% | — |
| CVE-2026-44616 | MED 6.5 | apache zeppelin LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint | 0.4% | — |
| CVE-2026-31417 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging `fragment_queue` in `x2 | 0.4% | — |
| CVE-2026-30912 | HIGH 7.5 | apache airflow In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, wh | 0.4% | — |
| CVE-2026-23242 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_dat | 0.4% | — |
| CVE-2025-53726 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53724 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53152 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-21360 | HIGH 7.8 | microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-49864 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thread creation In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This is a problem, however | 0.4% | — |
| CVE-2024-25709 | MED 6.1 | esri portal_for_arcgis There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could | 0.4% | — |
| CVE-2023-41676 | MED 4.3 | fortinet fortisiem An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs. | 0.4% | — |
| CVE-2023-20037 | MED 5.4 | cisco industrial_network_director A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An att | 0.4% | — |
| CVE-2022-44699 | MED 5.5 | microsoft azure_network_watcher_agent Azure Network Watcher Agent Security Feature Bypass Vulnerability | 0.4% | — |
| CVE-2022-38412 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu | 0.4% | — |
| CVE-2022-34706 | HIGH 7.8 | microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-23439 | MED 4.7 | fortinet fortiadc A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | 0.4% | — |
| CVE-2022-20787 | MED 5.7 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request for | 0.4% | — |
| CVE-2022-20742 | HIGH 7.4 | cisco adaptive_security_appliance_software A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerab | 0.4% | — |
| CVE-2021-39090 | MED 5.9 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive | 0.4% | — |
| CVE-2021-23175 | HIGH 8.2 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information d | 0.4% | — |