IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2018-3665 MED 5.6 canonical ubuntu_linux System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. 0.6%
CVE-2026-62839 MED 6.5 microsoft sharepoint_server Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2026-50203 CRIT 9.1 apache apache-airflow-providers-sftp A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow 0.6%
CVE-2025-54905 HIGH 7.1 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2024-43543 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.6%
CVE-2024-45537 MED 6.5 apache druid Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of allowed prop 0.6%
CVE-2024-34094 HIGH 7.8 adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi 0.6%
CVE-2024-30055 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.6%
CVE-2024-26853 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT When a frame can not be transmitted in XDP_REDIRECT (e.g. due to a full queue), it is necessary to free it by calling xdp_return_frame_rx_nap 0.6%
CVE-2023-28985 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receip 0.6%
CVE-2023-23555 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can c 0.6%
CVE-2023-22842 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel ( 0.6%
CVE-2023-22839 HIGH 7.5 f5 big-ip_10000s_firmware On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN co 0.6%
CVE-2023-22664 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in mem 0.6%
CVE-2023-22422 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Tra 0.6%
CVE-2023-22341 HIGH 7.5 f5 big-ip_access_policy_manager On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references 0.6%
CVE-2023-22340 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software vers 0.6%
CVE-2023-22281 HIGH 7.5 f5 big-ip_advanced_firewall_manager On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cau 0.6%
CVE-2022-20691 MED 5.3 cisco ata_190_firmware A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerability is due to missing l 0.6%
CVE-2020-7875 HIGH 7.5 dext5 dext5upload DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution. 0.6%
CVE-2020-3536 MED 5.4 cisco sd-wan A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based 0.6%
CVE-2026-57098 HIGH 7.5 microsoft remote_desktop_client Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-65768 HIGH 8.8 microsoft teams Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62824 HIGH 8.8 microsoft windows_10_1607 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-61363 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%