IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-20804 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%
CVE-2026-20167 HIGH 7.7 cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error ha 0.3%
CVE-2026-20105 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaus 0.3%
CVE-2026-20100 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN con 0.3%
CVE-2026-20049 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all 0.3%
CVE-2026-20014 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the avail 0.3%
CVE-2026-19306 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload 0.4%
CVE-2026-19304 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. 0.3%
CVE-2025-59500 HIGH 7.7 microsoft azure_notification_service Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-59200 HIGH 7.7 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. 0.8%
CVE-2025-55698 HIGH 7.7 microsoft windows_11_24h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. 1.1%
CVE-2025-53781 HIGH 7.7 microsoft dcadsv5-series_azure_vm_firmware Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-53139 HIGH 7.7 microsoft windows_10_21h2 Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2025-49218 HIGH 7.7 trendmicro trend_micro_endpoint_encryption A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not identical to CVE-2025-49215. Please note: an attacker must firs 0.1%
CVE-2025-49211 HIGH 7.7 trendmicro trend_micro_endpoint_encryption A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target 0.1%
CVE-2025-3937 HIGH 7.7 tridium niagara Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, 0.3%
CVE-2025-38413 HIGH 7.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: xsk: rx: fix the frame's length check When calling buf_to_xdp, the len argument is the frame data's length without virtio header's length (vi->hdr_len). We check that len with 0.2%
CVE-2025-29833 HIGH 7.7 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-22222 HIGH 7.7 vmware aria_operations VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. 0.6%
CVE-2025-20352 HIGH 7.7 cisco ios A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on 39.4%
CVE-2025-20176 HIGH 7.7 cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques 0.8%
CVE-2025-20175 HIGH 7.7 cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques 0.8%
CVE-2025-20174 HIGH 7.7 cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques 0.8%
CVE-2025-20173 HIGH 7.7 cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques 0.8%
CVE-2025-20172 HIGH 7.7 cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling 0.8%