IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-59173 HIGH 7.5 apache traffic_server Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. 0.7%
CVE-2026-43868 MED 5.3 apache thrift Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.7%
CVE-2026-33120 HIGH 8.8 microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-20821 MED 6.2 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. 0.7%
CVE-2025-24042 HIGH 7.3 microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability 0.7%
CVE-2025-21288 MED 6.5 microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability 0.7%
CVE-2025-21272 MED 6.5 microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability 0.7%
CVE-2024-52056 MED 6.5 wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file. 0.7%
CVE-2024-44986 HIGH 8.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m 0.7%
CVE-2023-26211 MED 6.8 fortinet fortisoar An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. 0.7%
CVE-2024-37087 MED 5.3 vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. 0.7%
CVE-2024-20658 HIGH 7.8 microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability 0.7%
CVE-2023-36770 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2021-41347 HIGH 7.8 microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability 0.7%
CVE-2021-28349 HIGH 7.8 microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability 0.7%
CVE-2021-28348 HIGH 7.8 microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability 0.7%
CVE-2020-1364 HIGH 7.1 microsoft windows_10 A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. 0.7%
CVE-2020-12826 MED 5.3 canonical ubuntu_linux A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can s 0.7%
CVE-2019-5592 MED 5.9 fortinet fortios_ips_engine Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, when configured with SSL Deep Inspection po 0.7%
CVE-2019-1695 MED 6.5 cisco adaptive_security_appliance_software A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulne 0.7%
CVE-2026-67368 HIGH 8.8 microsoft sql_server_2017 Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-32186 CRIT 10.0 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-33107 CRIT 10.0 microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2024-35178 HIGH 7.5 jupyter jupyter_server The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this pas 0.7%
CVE-2024-28148 MED 4.3 apache superset An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, wh 0.7%