IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-20827 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. 0.7%
CVE-2026-20823 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.7%
CVE-2025-26683 HIGH 8.1 microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2024-23590 CRIT 9.1 apache kylin Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue. 0.7%
CVE-2024-35797 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in 0.7%
CVE-2022-48658 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context. Commit 5a836bf6b09f ("mm: slub: move flush_cpu_slab() invocations __free_slab() invocations out of IRQ context") mov 0.7%
CVE-2023-34056 MED 4.3 vmware vcenter_server vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. 0.7%
CVE-2022-45797 HIGH 7.1 trendmicro apex_one An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an att 0.7%
CVE-2022-23293 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0.7%
CVE-2019-1565 MED 5.4 paloaltonetworks pan-os The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to in 0.7%
CVE-2026-63523 MED 6.5 microsoft skype_for_business_server Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2026-69813 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-13448 HIGH 8.1 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate 0.7%
CVE-2025-22219 MED 6.8 vmware aria_operations_for_logs VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations 0.7%
CVE-2024-43625 HIGH 8.1 microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability 0.7%
CVE-2022-23296 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.7%
CVE-2021-1421 HIGH 7.8 cisco enterprise_nfv_infrastructure_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to a co 0.7%
CVE-2020-3465 HIGH 7.4 cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this vulnerabil 0.7%
CVE-2019-15291 MED 4.6 linux linux_kernel An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver. 0.7%
CVE-2018-7492 MED 5.5 canonical ubuntu_linux A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST. 0.7%
CVE-2016-1280 MED 6.5 juniper junos PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1R4, 1 0.7%
CVE-2026-69486 HIGH 8.8 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-69415 MED 6.8 microsoft windows_10_1607 Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-56162 CRIT 10.0 microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-14499 HIGH 8.8 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component. 0.7%