IT
57.399 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.399 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-45483 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45479 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45468 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45467 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45462 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2025-62198 MED 5.4 apache atlas An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue. 0.5%
CVE-2025-48812 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-39682 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next recor 0.5%
CVE-2025-22088 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the erdma_cep_put(new_cep) being called, new_cep will be freed, and the following dereference will cause a UAF problem. Fix 0.5%
CVE-2024-22270 HIGH 7.1 vmware fusion VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained 0.5%
CVE-2024-22269 HIGH 7.1 vmware fusion VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a 0.5%
CVE-2024-20501 HIGH 8.6 cisco meraki_mx100_firmware Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. The 0.5%
CVE-2024-20499 HIGH 8.6 cisco meraki_mx100_firmware Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. The 0.5%
CVE-2024-20498 HIGH 8.6 cisco meraki_mx100_firmware Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. The 0.5%
CVE-2023-20114 MED 6.5 cisco secure_firewall_management_center A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An atta 0.5%
CVE-2022-37986 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 0.5%
CVE-2022-22959 MED 4.3 vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. 0.5%
CVE-2021-34471 HIGH 7.8 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0.5%
CVE-2018-25020 HIGH 7.8 linux linux_kernel The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c 0.5%
CVE-2014-5472 MED 4.0 linux linux_kernel The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry. 0.5%
CVE-2014-5471 MED 4.0 linux linux_kernel Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 ima 0.5%
CVE-2012-3510 MED 5.6 linux linux_kernel Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKST 0.5%
CVE-2003-1428 MED 4.8 bharat_mediratta gallery Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos. 0.5%
CVE-2026-62778 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-59084 CRIT 9.1 apache tomcat Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1. 0.5%