57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-20192 | CRIT 9.6 | cisco telepresence_video_communication_server Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write creden | 0.7% | — |
| CVE-2022-41334 | HIGH 8.8 | fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of | 0.7% | — |
| CVE-2022-35728 | HIGH 8.1 | f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain v | 0.7% | — |
| CVE-2022-21928 | MED 6.3 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21868 | HIGH 7.0 | microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-43880 | MED 5.5 | microsoft windows_11 Windows Mobile Device Management Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-24212 | HIGH 7.5 | nvidia isaac_launchable NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | 0.7% | — |
| CVE-2025-66335 | MED 5.3 | apache doris_mcp_server Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP | 0.7% | — |
| CVE-2026-25180 | MED 5.5 | microsoft 365_copilot Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-68438 | HIGH 7.5 | apache airflow In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a se | 0.7% | — |
| CVE-2025-48795 | MED 5.6 | apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic | 0.7% | — |
| CVE-2022-49260 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as settin | 0.7% | — |
| CVE-2024-43501 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38612 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist | 0.7% | — |
| CVE-2024-29061 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2023-32037 | MED 6.5 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2020-8428 | HIGH 7.1 | linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope | 0.7% | — |
| CVE-2026-56287 | HIGH 8.1 | apache fineract A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation | 0.7% | — |
| CVE-2026-50502 | HIGH 8.0 | microsoft windows_10_1607 Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-43866 | HIGH 7.3 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms | 0.7% | — |
| CVE-2026-24072 | HIGH 8.8 | apache http_server An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 0.7% | — |
| CVE-2023-22633 | HIGH 7.5 | fortinet fortinac An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attac | 0.7% | — |
| CVE-2023-26269 | HIGH 7.8 | apache james Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that ver | 0.7% | — |
| CVE-2023-21807 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-22416 | HIGH 7.5 | juniper junos A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On all MX Series and SRX Series platform with SIP ALG enabled, when a malformed SIP packet is received, | 0.7% | — |