57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.918 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-0783 | MED 4.2 | apache tomcat Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files | 0.8% | — |
| CVE-2026-58612 | HIGH 7.4 | microsoft powershell Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-57104 | HIGH 8.8 | microsoft azure_storage_explorer Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-47896 | HIGH 7.5 | apache lucene.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recomm | 0.8% | — |
| CVE-2022-22206 | HIGH 7.5 | juniper junos A Buffer Overflow vulnerability in the PFE of Juniper Networks Junos OS on SRX series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). The PFE will crash when specific traffic is scanned by Enhanced Web Filtering safe-search | 0.8% | — |
| CVE-2022-21903 | HIGH 7.0 | microsoft windows_10 Windows GDI Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-5935 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performi | 0.8% | — |
| CVE-2020-5854 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made. | 0.8% | — |
| CVE-2019-12579 | HIGH 7.8 | londontrustmedia private_internet_access_vpn_client A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is set | 0.8% | — |
| CVE-2019-12578 | HIGH 7.8 | londontrustmedia private_internet_access_vpn_client A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /o | 0.8% | — |
| CVE-2019-1647 | HIGH 8.0 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected | 0.8% | — |
| CVE-2008-1299 | MED 6.1 | manageengine servicedesk_plus Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information i | 0.8% | — |
| CVE-2026-65660 | HIGH 8.8 | microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-8481 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() | 0.8% | — |
| CVE-2026-25087 | HIGH 7.0 | apache arrow Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadi | 0.8% | — |
| CVE-2025-65082 | MED 6.5 | apache http_server Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects A | 0.8% | — |
| CVE-2025-21373 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36732 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26805 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-38651 | CRIT 9.8 | vmware hyperic_server A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects pro | 0.8% | — |
| CVE-2021-36190 | MED 5.5 | fortinet fortiweb A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests. | 0.8% | — |
| CVE-2021-41373 | MED 5.5 | microsoft fslogix FSLogix Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31373 | HIGH 8.0 | juniper junos A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive da | 0.8% | — |
| CVE-2021-31355 | HIGH 8.0 | juniper junos A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administrat | 0.8% | — |
| CVE-2021-34466 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.8% | — |