56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.747 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-39860 | CRIT 9.0 | nixos nix Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) | 0.2% | — |
| CVE-2026-33844 | CRIT 9.0 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-26149 | CRIT 9.0 | microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-20267 | CRIT 9.0 | cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern | 0.3% | — |
| CVE-2025-59978 | CRIT 9.0 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execut | 0.6% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-47158 | CRIT 9.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-36038 | CRIT 9.0 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. | 9.8% | — |
| CVE-2025-3500 | CRIT 9.0 | avast antivirus Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. | 0.5% | — |
| CVE-2025-21198 | CRIT 9.0 | microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-20363 | CRIT 9.0 | cisco adaptive_security_appliance_software A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, r | 6.9% | — |
| CVE-2024-52577 | CRIT 9.0 | apache ignite In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose cla | 2.7% | — |
| CVE-2024-48886 | CRIT 9.0 | fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver | 0.5% | — |
| CVE-2024-47572 | CRIT 9.0 | fortinet fortisoar An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file | 0.6% | — |
| CVE-2024-38220 | CRIT 9.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-38182 | CRIT 9.0 | microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38124 | CRIT 9.0 | microsoft windows_server_2008 Windows Netlogon Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2024-29990 | CRIT 9.0 | microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 18.0% | — |
| CVE-2024-21403 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-21400 | CRIT 9.0 | microsoft confidental_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2024-21376 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-0132 | CRIT 9.0 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases whe | 38.7% | — |
| CVE-2024-0095 | CRIT 9.0 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, d | 0.5% | — |
| CVE-2024-0087 | CRIT 9.0 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denia | 19.9% | — |
| CVE-2023-48692 | CRIT 9.0 | microsoft azure_rtos_netx_duo Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include p | 3.1% | — |