IT
57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.436 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-31193 HIGH 7.8 microsoft windows_10 Windows SSDP Service Elevation of Privilege Vulnerability 0.5%
CVE-2021-29683 MED 6.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. 0.5%
CVE-2019-15924 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure. 0.5%
CVE-2018-0381 MED 6.8 cisco aironet_access_points A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadloc 0.5%
CVE-2013-4163 MED 4.7 linux linux_kernel The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a 0.5%
CVE-2008-1932 MED 6.8 realtek hd_audio_codec_drivers Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request. 0.5%
CVE-2026-68569 HIGH 8.1 apache tomcat Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 thr 0.5%
CVE-2026-65811 HIGH 8.8 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-55145 MED 6.3 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. 0.5%
CVE-2026-55122 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-49875 CRIT 9.8 apache cxf Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 o 0.5%
CVE-2026-46119 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treate 0.5%
CVE-2026-40411 CRIT 9.9 microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-31995 MED 5.3 openclaw openclaw OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger 0.5%
CVE-2025-33065 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33063 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33061 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33060 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33059 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33058 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33052 MED 5.5 microsoft windows_10_1809 Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24853 HIGH 7.5 apache jspwiki A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team s 0.5%
CVE-2025-24069 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2024-45112 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is acc 0.5%
CVE-2023-28597 HIGH 8.3 zoom rooms Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the vi 0.5%