IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-35561 HIGH 7.4 amazon athena_odbc Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-ba 0.5%
CVE-2026-35560 HIGH 7.4 amazon athena_odbc Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when 0.3%
CVE-2026-33797 HIGH 7.4 juniper junos An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial o 0.2%
CVE-2026-33771 HIGH 7.4 juniper ctp_operating_system A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The p 0.3%
CVE-2026-32156 HIGH 7.4 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-2713 HIGH 7.4 ibm trusteer_rapport IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an 0.1%
CVE-2026-25167 HIGH 7.4 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-24281 HIGH 7.4 apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It 0.6%
CVE-2026-23364 HIGH 7.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq(). 0.4%
CVE-2026-21524 HIGH 7.4 microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-21521 HIGH 7.4 microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-20853 HIGH 7.4 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-20844 HIGH 7.4 microsoft windows_10_1607 Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-20222 HIGH 7.4 A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly 0.2%
CVE-2026-20074 HIGH 7.4 cisco ios_xr A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due 0.2%
CVE-2026-19139 HIGH 7.4 google chrome Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) 0.1%
CVE-2026-10968 HIGH 7.4 google chrome Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-0296 HIGH 7.4 paloaltonetworks globalprotect Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The Global 0.1%
CVE-2025-59960 HIGH 7.4 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial o 0.3%
CVE-2025-59489 HIGH 7.4 unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run 0.6%
CVE-2025-59210 HIGH 7.4 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability 0.3%
CVE-2025-59206 HIGH 7.4 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability 0.4%
CVE-2025-59189 HIGH 7.4 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2025-55693 HIGH 7.4 microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 2.0%
CVE-2025-55687 HIGH 7.4 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. 0.3%