IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-49086 MED 6.5 apache camel Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name 0.7%
CVE-2026-50628 CRIT 9.8 apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recomme 0.7%
CVE-2025-37879 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read co 0.7%
CVE-2024-38203 MED 6.2 microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability 0.7%
CVE-2024-43497 HIGH 8.4 microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability 0.7%
CVE-2024-22234 HIGH 7.4 vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl 0.7%
CVE-2023-44253 MED 5.0 fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow 0.7%
CVE-2023-36773 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-36772 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-36771 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-20200 HIGH 7.7 cisco firepower_4112_firmware A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to 0.7%
CVE-2023-24513 MED 6.5 arista cloudeos On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are 0.7%
CVE-2022-22246 HIGH 7.5 juniper junos A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabilities, and by 0.7%
CVE-2020-4926 CRIT 9.1 ibm elastic_storage_system A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. 0.7%
CVE-2022-29132 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7%
CVE-2017-0620 HIGH 7.0 google android An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr 0.7%
CVE-2024-38215 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-38135 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.7%
CVE-2024-38134 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 0.7%
CVE-2021-47478 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le 0.7%
CVE-2024-27439 MED 6.5 apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo 0.7%
CVE-2023-35315 HIGH 8.8 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability 0.7%
CVE-2023-28296 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.7%
CVE-2022-21967 HIGH 7.0 microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability 0.7%
CVE-2021-29773 MED 5.4 ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. 0.7%