57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.490 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20872 | MED 6.5 | microsoft windows_10_1607 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 20.1% | — |
| CVE-2026-20847 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. | 1.4% | — |
| CVE-2026-20812 | MED 6.5 | microsoft windows_10_1607 Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | 1.1% | — |
| CVE-2026-20288 | MED 6.5 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&n | 0.4% | — |
| CVE-2026-20262 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affe | 28.2% | |
| CVE-2026-20168 | MED 6.5 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficie | 0.3% | — |
| CVE-2026-20133 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmi | 31.4% | |
| CVE-2026-20097 | MED 6.5 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied inpu | 0.4% | — |
| CVE-2026-20096 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi | 0.7% | — |
| CVE-2026-20095 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi | 0.9% | — |
| CVE-2026-20081 | MED 6.5 | cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These | 0.4% | — |
| CVE-2026-20078 | MED 6.5 | cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These | 0.4% | — |
| CVE-2026-20064 | MED 6.5 | cisco secure_firewall_threat_defense A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation | 0.1% | — |
| CVE-2026-20042 | MED 6.5 | cisco nexus_dashboard A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentica | 0.3% | — |
| CVE-2026-19302 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | 0.5% | — |
| CVE-2026-19299 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. | 0.5% | — |
| CVE-2026-18652 | MED 6.5 | Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read | 0.3% | — |
| CVE-2026-17992 | MED 6.5 | google chrome Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-17846 | MED 6.5 | google chrome Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-17707 | MED 6.5 | google chrome Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severit | 0.5% | — |
| CVE-2026-17622 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | 0.5% | — |
| CVE-2026-14470 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | 0.3% | — |
| CVE-2026-14402 | MED 6.5 | google chrome Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-14384 | MED 6.5 | google chrome Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-14148 | MED 6.5 | google chrome Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |