56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-52449 | HIGH 8.5 | tableau tableau_server Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3 | 0.2% | — |
| CVE-2025-49717 | HIGH 8.5 | microsoft sql_server_2019 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-22218 | HIGH 8.5 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | 0.7% | — |
| CVE-2025-21416 | HIGH 8.5 | microsoft azure_virtual_desktop Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-20148 | HIGH 8.5 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to imp | 0.4% | — |
| CVE-2024-51954 | HIGH 8.5 | esri arcgis_server There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfedera | 0.3% | — |
| CVE-2024-50386 | HIGH 8.5 | apache cloudstack Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances. Due to missing validation checks for KVM-compatible templates in CloudStack 4.0.0 through 4.18.2.4 and 4.1 | 1.5% | — |
| CVE-2024-45219 | HIGH 8.5 | apache cloudstack Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks to their existing instances. Due to missing validation checks for KVM-compatible templates or volume | 1.2% | — |
| CVE-2024-43479 | HIGH 8.5 | microsoft power_automate Microsoft Power Automate Desktop Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38206 | HIGH 8.5 | microsoft copilot_studio An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | 12.3% | — |
| CVE-2024-32114 | HIGH 8.5 | apache activemq In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can i | 7.1% | — |
| CVE-2024-27894 | HIGH 8.5 | apache pulsar The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using t | 1.9% | — |
| CVE-2024-27135 | HIGH 8.5 | apache pulsar Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies | 6.0% | — |
| CVE-2024-25699 | HIGH 8.5 | esri arcgis_enterprise There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes, which under unique circumstances could a | 0.7% | — |
| CVE-2024-23673 | HIGH 8.5 | apache sling_servlets_resolver Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact | 1.3% | — |
| CVE-2024-22280 | HIGH 8.5 | vmware aria_automation VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database. | 0.5% | — |
| CVE-2023-41679 | HIGH 8.5 | fortinet fortimanager An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device manag | 0.5% | — |
| CVE-2023-25925 | HIGH 8.5 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632. | 1.4% | — |
| CVE-2023-25921 | HIGH 8.5 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620. | 1.1% | — |
| CVE-2023-22374 | HIGH 8.5 | f5 big-ip_access_policy_manager A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attac | 72.6% | — |
| CVE-2022-41127 | HIGH 8.5 | microsoft dynamics_365_business_central Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-41076 | HIGH 8.5 | microsoft powershell PowerShell Remote Code Execution Vulnerability | 61.6% | — |
| CVE-2022-31764 | HIGH 8.5 | apache shardingsphere_elasticjob-ui The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed i | 0.7% | — |
| CVE-2022-30163 | HIGH 8.5 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2022-28182 | HIGH 8.5 | nvidia gpu_display_driver NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code executi | 1.6% | — |