IT
57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.825 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-69518 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-59775 HIGH 7.5 apache http_server Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recomme 0.8%
CVE-2025-22829 MED 4.3 apache cloudstack The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable r 0.8%
CVE-2024-45384 MED 5.3 apache druid Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by 0.8%
CVE-2023-52696 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. 0.8%
CVE-2023-4576 HIGH 8.6 mozilla firefox On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating syste 0.8%
CVE-2013-2268 HIGH 7.5 google chrome Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." 0.8%
CVE-2026-78525 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-78505 HIGH 8.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-73006 HIGH 8.8 microsoft windows_10_1607 Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69860 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69797 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69767 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69678 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69632 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-61483 HIGH 7.5 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alt 0.8%
CVE-2025-47997 MED 6.5 microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. 0.8%
CVE-2025-29822 HIGH 7.8 microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. 0.8%
CVE-2022-49561 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't foun 0.8%
CVE-2022-41079 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 0.8%
CVE-2022-41078 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 0.8%
CVE-2022-26116 HIGH 7.2 fortinet fortinac Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 an 0.8%
CVE-2022-26914 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 0.8%
CVE-2022-24546 HIGH 7.8 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0.8%
CVE-2022-23014 MED 6.5 f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End o 0.8%