IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-20192 CRIT 9.6 cisco telepresence_video_communication_server Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write creden 0.7%
CVE-2022-41334 HIGH 8.8 fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of 0.7%
CVE-2022-35728 HIGH 8.1 f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain v 0.7%
CVE-2022-21928 MED 6.3 microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2022-21868 HIGH 7.0 microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability 0.7%
CVE-2021-43880 MED 5.5 microsoft windows_11 Windows Mobile Device Management Elevation of Privilege Vulnerability 0.7%
CVE-2026-24212 HIGH 7.5 nvidia isaac_launchable NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. 0.7%
CVE-2025-66335 MED 5.3 apache doris_mcp_server Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP 0.7%
CVE-2026-25180 MED 5.5 microsoft 365_copilot Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. 0.7%
CVE-2025-68438 HIGH 7.5 apache airflow In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a se 0.7%
CVE-2025-48795 MED 5.6 apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic 0.7%
CVE-2022-49260 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as settin 0.7%
CVE-2024-43501 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-38612 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist 0.7%
CVE-2024-29061 HIGH 7.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2023-32037 MED 6.5 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability 0.7%
CVE-2020-8428 HIGH 7.1 linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope 0.7%
CVE-2026-56287 HIGH 8.1 apache fineract A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation 0.7%
CVE-2026-50502 HIGH 8.0 microsoft windows_10_1607 Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-43866 HIGH 7.3 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms 0.7%
CVE-2026-24072 HIGH 8.8 apache http_server An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue. 0.7%
CVE-2023-22633 HIGH 7.5 fortinet fortinac An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attac 0.7%
CVE-2023-26269 HIGH 7.8 apache james Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that ver 0.7%
CVE-2023-21807 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7%
CVE-2023-22416 HIGH 7.5 juniper junos A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On all MX Series and SRX Series platform with SIP ALG enabled, when a malformed SIP packet is received, 0.7%