58.181 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.181 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-0272 | HIGH 7.2 | paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is | 0.3% | — |
| CVE-2026-0261 | HIGH 7.2 | paloaltonetworks pan-os Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the | 1.4% | — |
| CVE-2026-0241 | HIGH 7.2 | paloaltonetworks trust_protection_foundation Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources. | 0.3% | — |
| CVE-2025-68648 | HIGH 7.2 | fortinet fortianalyzer A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 th | 0.6% | — |
| CVE-2025-66178 | HIGH 7.2 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 thro | 1.7% | — |
| CVE-2025-64676 | HIGH 7.2 | microsoft purview '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-64156 | HIGH 7.2 | fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticate | 0.3% | — |
| CVE-2025-64153 | HIGH 7.2 | fortinet fortiextender_firmware A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authentic | 1.7% | — |
| CVE-2025-61848 | HIGH 7.2 | fortinet fortianalyzer An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyze | 0.5% | — |
| CVE-2025-59922 | HIGH 7.2 | fortinet forticlientems An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS | 7.8% | — |
| CVE-2025-58034 | HIGH 7.2 | fortinet fortiweb An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2 | 55.6% | |
| CVE-2025-57738 | HIGH 7.2 | apache syncope Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being p | 23.2% | — |
| CVE-2025-53949 | HIGH 7.2 | fortinet fortisandbox An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 a | 17.2% | — |
| CVE-2025-53779 | HIGH 7.2 | microsoft windows_server_2025 Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 2.7% | — |
| CVE-2025-53744 | HIGH 7.2 | fortinet fortios An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escal | 0.6% | — |
| CVE-2025-53681 | HIGH 7.2 | fortinet fortimail An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privil | 0.4% | — |
| CVE-2025-53679 | HIGH 7.2 | fortinet fortisandbox An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 a | 12.3% | — |
| CVE-2025-52983 | HIGH 7.2 | juniper junos A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device. On VM Host Routing Engines (RE), even if the configured public key for root | 0.6% | — |
| CVE-2025-49813 | HIGH 7.2 | fortinet fortiadc An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code | 1.1% | — |
| CVE-2025-49666 | HIGH 7.2 | microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-47856 | HIGH 7.2 | fortinet fortivoice Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or comman | 1.3% | — |
| CVE-2025-4615 | HIGH 7.2 | paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu | 0.8% | — |
| CVE-2025-4231 | HIGH 7.2 | paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit th | 1.0% | — |
| CVE-2025-3944 | HIGH 7.2 | tridium niagara Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Ni | 0.5% | — |
| CVE-2025-36048 | HIGH 7.2 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | 0.5% | — |