IT
57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.490 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-20872 MED 6.5 microsoft windows_10_1607 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 20.1%
CVE-2026-20847 MED 6.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. 1.4%
CVE-2026-20812 MED 6.5 microsoft windows_10_1607 Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. 1.1%
CVE-2026-20288 MED 6.5 cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&n 0.4%
CVE-2026-20262 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affe 28.2%
CVE-2026-20168 MED 6.5 cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficie 0.3%
CVE-2026-20133 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmi 31.4%
CVE-2026-20097 MED 6.5 cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied inpu 0.4%
CVE-2026-20096 MED 6.5 cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi 0.7%
CVE-2026-20095 MED 6.5 cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi 0.9%
CVE-2026-20081 MED 6.5 cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.  These 0.4%
CVE-2026-20078 MED 6.5 cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.  These 0.4%
CVE-2026-20064 MED 6.5 cisco secure_firewall_threat_defense A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation 0.1%
CVE-2026-20042 MED 6.5 cisco nexus_dashboard A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentica 0.3%
CVE-2026-19302 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. 0.5%
CVE-2026-19299 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. 0.5%
CVE-2026-18652 MED 6.5 Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read 0.3%
CVE-2026-17992 MED 6.5 google chrome Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) 0.3%
CVE-2026-17846 MED 6.5 google chrome Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) 0.2%
CVE-2026-17707 MED 6.5 google chrome Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severit 0.5%
CVE-2026-17622 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. 0.5%
CVE-2026-14470 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. 0.3%
CVE-2026-14402 MED 6.5 google chrome Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-14384 MED 6.5 google chrome Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2026-14148 MED 6.5 google chrome Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) 0.3%