IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-7573 MED 5.0 rapid7 velociraptor An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations 0.3%
CVE-2026-61368 MED 5.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-45502 MED 5.0 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 20.3%
CVE-2026-40974 MED 5.0 vmware spring_boot Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 0.2%
CVE-2026-40971 MED 5.0 vmware spring_boot When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory. 0.2%
CVE-2026-40970 MED 5.0 vmware spring_boot When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory. 0.1%
CVE-2026-28717 MED 5.0 acronis cyber_protect Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. 0.1%
CVE-2026-25228 MED 5.0 signalk signal_k_server Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and dir 0.4%
CVE-2026-11281 MED 5.0 google chrome Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low) 0.1%
CVE-2026-0385 MED 5.0 microsoft edge_chromium Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability 0.2%
CVE-2025-62453 MED 5.0 microsoft visual_studio_code Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2025-59198 MED 5.0 microsoft windows_10_1507 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. 0.4%
CVE-2025-30474 MED 5.0 apache commons_vfs Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mas 0.9%
CVE-2025-24788 MED 5.0 snowflake snowflake_connector snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them a 0.1%
CVE-2025-20348 MED 5.0 cisco nexus_dashboard A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. 0.3%
CVE-2025-13995 MED 5.0 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. 0.2%
CVE-2024-50570 MED 5.0 fortinet forticlient A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local aut 0.1%
CVE-2024-47250 MED 5.0 apache nimble Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluetooth 0.7%
CVE-2024-47249 MED 5.0 apache nimble Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is 0.6%
CVE-2024-45383 MED 5.0 microsoft high_definition_audio_bus_driver A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a loc 1.5%
CVE-2024-43520 MED 5.0 microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability 1.0%
CVE-2024-39544 MED 5.0 juniper junos_os_evolved An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view NETCONF traceoptions files, representing an exposure of sensitive information. On all Juno 0.2%
CVE-2024-29991 MED 5.0 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0.6%
CVE-2024-26220 MED 5.0 microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability 1.1%
CVE-2024-24855 MED 5.0 linux linux_kernel A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. 0.2%