57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.825 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69518 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-59775 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recomme | 0.8% | — |
| CVE-2025-22829 | MED 4.3 | apache cloudstack The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable r | 0.8% | — |
| CVE-2024-45384 | MED 5.3 | apache druid Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by | 0.8% | — |
| CVE-2023-52696 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. | 0.8% | — |
| CVE-2023-4576 | HIGH 8.6 | mozilla firefox On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating syste | 0.8% | — |
| CVE-2013-2268 | HIGH 7.5 | google chrome Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." | 0.8% | — |
| CVE-2026-78525 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78505 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-73006 | HIGH 8.8 | microsoft windows_10_1607 Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69860 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69797 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69767 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69678 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69632 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-61483 | HIGH 7.5 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alt | 0.8% | — |
| CVE-2025-47997 | MED 6.5 | microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-29822 | HIGH 7.8 | microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2022-49561 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't foun | 0.8% | — |
| CVE-2022-41079 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-41078 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-26116 | HIGH 7.2 | fortinet fortinac Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 an | 0.8% | — |
| CVE-2022-26914 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-24546 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-23014 | MED 6.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End o | 0.8% | — |