IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-68778 MED 6.5 microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-68777 MED 6.5 microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-67393 MED 6.5 microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-67369 MED 6.5 microsoft sql_server_2025 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-47303 HIGH 8.8 microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-58065 HIGH 8.1 apache apache-airflow-providers-git The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the se 0.7%
CVE-2024-43106 HIGH 7.1 microsoft excel A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger thi 0.7%
CVE-2024-42220 HIGH 7.1 microsoft outlook A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigg 0.7%
CVE-2024-41165 HIGH 7.1 microsoft word A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this 0.7%
CVE-2024-40937 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gve: Clear napi->skb before dev_kfree_skb_any() gve_rx_free_skb incorrectly leaves napi->skb referencing an skb after it is freed with dev_kfree_skb_any(). This can result in a subsequent ca 0.7%
CVE-2021-46999 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] 0.7%
CVE-2022-20794 MED 6.5 cisco roomos Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect u 0.7%
CVE-2020-1371 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of 0.7%
CVE-2020-1363 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vu 0.7%
CVE-2020-1352 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vu 0.7%
CVE-2019-18660 MED 4.7 canonical ubuntu_linux The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c. 0.7%
CVE-2026-62835 CRIT 9.3 microsoft azure_portal Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-37871 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nfsd: decrease sc_count directly if fail to queue dl_recall A deadlock warning occurred when invoking nfs4_put_stid following a failed dl_recall queue operation: T1 0.7%
CVE-2024-26851 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: Add protection for bmp length out of range UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts that are out of bounds for their data type. v 0.7%
CVE-2024-26845 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to tmr_list handling An abort that is responded to by iSCSI itself is added to tmr_list but does not go to target core. A LUN_RESET that goes through tmr_list tak 0.7%
CVE-2023-6546 HIGH 7.0 fedoraproject fedora A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem o 0.7%
CVE-2022-39950 HIGH 8.0 fortinet fortianalyzer An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege leve 0.7%
CVE-2020-15940 MED 4.1 fortinet forticlient_enterprise_management_server An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server. 0.7%
CVE-2019-7588 MED 6.7 exacq enterprise_system_manager A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM running on a Windows 0.7%
CVE-2018-17891 LOW 3.7 carestream carestream_vue_ris Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical informatio 0.7%