IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-35389 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 0.8%
CVE-2026-63071 CRIT 9.8 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affect 0.8%
CVE-2025-29803 HIGH 7.3 microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2024-38139 HIGH 8.7 microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2022-27486 MED 6.6 fortinet fortiddos A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 0.8%
CVE-2024-25090 MED 5.4 apache roller Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not 0.8%
CVE-2024-21340 MED 4.6 microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability 0.8%
CVE-2018-10878 HIGH 7.8 canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. 0.8%
CVE-2017-5646 MED 6.8 apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a 0.8%
CVE-2026-49163 HIGH 8.8 microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-21264 HIGH 7.1 microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.8%
CVE-2024-41036 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit 0.8%
CVE-2024-30341 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i 0.8%
CVE-2023-27497 CRIT 10.0 sap diagnostics_agent Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation 0.8%
CVE-2012-2853 MED 6.8 google chrome The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly hav 0.8%
CVE-2012-2847 MED 4.3 google chrome Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of ser 0.8%
CVE-2026-40021 MED 5.3 apache log4net Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitiz 0.8%
CVE-2026-25903 MED 6.6 apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi 0.8%
CVE-2026-20834 MED 4.6 microsoft windows_10_1607 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. 0.8%
CVE-2024-49044 MED 6.7 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.8%
CVE-2024-38166 HIGH 8.2 microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. 0.8%
CVE-2024-36288 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory 0.8%
CVE-2024-36471 HIGH 7.5 apache allura Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allur 0.8%
CVE-2023-32051 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.8%
CVE-2023-20030 MED 6.0 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or nega 0.8%