58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-2120 | MED 6.5 | microsoft windows_2000 Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a regi | 62.0% | — |
| CVE-2026-77891 | MED 6.4 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-77887 | MED 6.4 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-72947 | MED 6.4 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71338 | MED 6.4 | microsoft windows_10_1607 Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70582 | MED 6.4 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69878 | MED 6.4 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-62708 | MED 6.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0.3% | — |
| CVE-2026-60062 | MED 6.4 | f5 nginx_agent The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Ma | 0.3% | — |
| CVE-2026-57097 | MED 6.4 | microsoft windows_10_1607 Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2026-55000 | MED 6.4 | microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.3% | — |
| CVE-2026-47864 | MED 6.4 | vmware spring_integration SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read d | 5.9% | — |
| CVE-2026-21265 | MED 6.4 | microsoft windows_10_1607 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising | 1.1% | — |
| CVE-2026-20169 | MED 6.4 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient in | 0.2% | — |
| CVE-2025-58324 | MED 6.4 | fortinet fortisiem An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versio | 0.3% | — |
| CVE-2025-46776 | MED 6.4 | fortinet fortiextender_firmware A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated u | 0.2% | — |
| CVE-2025-3630 | MED 6.4 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed | 0.2% | — |
| CVE-2025-33097 | MED 6.4 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl | 0.2% | — |
| CVE-2025-32766 | MED 6.4 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands | 0.1% | — |
| CVE-2025-23227 | MED 6.4 | ibm tivoli_application_dependency_discovery_manager IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p | 0.2% | — |
| CVE-2025-21403 | MED 6.4 | microsoft on-prem_data_gateway On-Premises Data Gateway Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-20264 | MED 6.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficie | 0.4% | — |
| CVE-2024-8207 | MED 6.4 | mongodb mongodb In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-control | 0.2% | — |
| CVE-2024-49339 | MED 6.4 | ibm financial_transaction_manager_for_multiplatform IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the inten | 0.2% | — |
| CVE-2024-47120 | MED 6.4 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges. | 0.2% | — |