IT
56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.747 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-39860 CRIT 9.0 nixos nix Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) 0.2%
CVE-2026-33844 CRIT 9.0 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 1.0%
CVE-2026-26149 CRIT 9.0 microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2026-20267 CRIT 9.0 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0.3%
CVE-2025-59978 CRIT 9.0 juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execut 0.6%
CVE-2025-55244 CRIT 9.0 microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability 0.6%
CVE-2025-47158 CRIT 9.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-36038 CRIT 9.0 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. 9.8%
CVE-2025-3500 CRIT 9.0 avast antivirus Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. 0.5%
CVE-2025-21198 CRIT 9.0 microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 0.9%
CVE-2025-20363 CRIT 9.0 cisco adaptive_security_appliance_software A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, r 6.9%
CVE-2024-52577 CRIT 9.0 apache ignite In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose cla 2.7%
CVE-2024-48886 CRIT 9.0 fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver 0.5%
CVE-2024-47572 CRIT 9.0 fortinet fortisoar An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file 0.6%
CVE-2024-38220 CRIT 9.0 microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability 1.0%
CVE-2024-38182 CRIT 9.0 microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. 0.9%
CVE-2024-38124 CRIT 9.0 microsoft windows_server_2008 Windows Netlogon Elevation of Privilege Vulnerability 1.2%
CVE-2024-29990 CRIT 9.0 microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 18.0%
CVE-2024-21403 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 1.3%
CVE-2024-21400 CRIT 9.0 microsoft confidental_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 2.2%
CVE-2024-21376 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability 1.2%
CVE-2024-0132 CRIT 9.0 nvidia nvidia_container_toolkit NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases whe 38.7%
CVE-2024-0095 CRIT 9.0 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, d 0.5%
CVE-2024-0087 CRIT 9.0 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denia 19.9%
CVE-2023-48692 CRIT 9.0 microsoft azure_rtos_netx_duo Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include p 3.1%