57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21835 | HIGH 7.8 | microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-67370 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-62817 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2026-42527 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' | 0.7% | — |
| CVE-2026-24266 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |
| CVE-2025-37928 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function cal | 0.7% | — |
| CVE-2024-41783 | CRIT 9.1 | ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input. | 0.7% | — |
| CVE-2024-20459 | MED 6.5 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying op | 0.7% | — |
| CVE-2023-22285 | HIGH 7.5 | intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-20270 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies | 0.7% | — |
| CVE-2023-32016 | MED 5.5 | microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-29341 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29340 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24905 | HIGH 7.8 | microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-32603 | HIGH 8.8 | fortinet fortianalyzer A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and servic | 0.7% | — |
| CVE-2021-26860 | HIGH 7.8 | microsoft windows_10 Windows App-V Overlay Filter Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1227 | HIGH 8.1 | cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API | 0.7% | — |
| CVE-2021-1255 | MED 4.6 | cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the | 0.7% | — |
| CVE-2020-25221 | HIGH 7.8 | linux linux_kernel get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow | 0.7% | — |
| CVE-2018-0006 | MED 6.5 | juniper junos A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by atte | 0.7% | — |
| CVE-2011-2204 | LOW 1.9 | apache tomcat Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information b | 0.7% | — |
| CVE-2026-70465 | HIGH 8.1 | fortinet forticlient A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS respons | 0.7% | — |
| CVE-2026-66909 | CRIT 9.8 | apache cxf Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized obj | 0.7% | — |
| CVE-2025-57735 | CRIT 9.1 | apache airflow When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who ar | 0.7% | — |
| CVE-2026-20838 | MED 5.5 | microsoft windows_11_23h2 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |