IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-31994 HIGH 7.1 openclaw openclaw OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handling of cmd metacharacters and expansion-sensitive characters in gateway.cmd files. Local attackers with control 0.6%
CVE-2025-68648 HIGH 7.2 fortinet fortianalyzer A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 th 0.6%
CVE-2025-59211 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-59186 MED 5.5 microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-55336 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-48800 MED 6.8 microsoft windows_10_1507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.6%
CVE-2025-48003 MED 6.8 microsoft windows_10_1809 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.6%
CVE-2025-50213 CRIT 9.8 apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad 0.6%
CVE-2025-22025 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: put dl_stid if fail to queue dl_recall Before calling nfsd4_run_cb to queue dl_recall to the callback_wq, we increment the reference count of dl_stid. We expect that after the correspo 0.6%
CVE-2024-38022 HIGH 7.0 microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability 0.6%
CVE-2024-30069 MED 4.7 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.6%
CVE-2024-21598 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If a BGP update 0.6%
CVE-2022-42722 MED 5.5 debian debian_linux In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices. 0.6%
CVE-2022-20629 MED 5.4 cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabiliti 0.6%
CVE-2022-20628 MED 5.4 cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabiliti 0.6%
CVE-2022-20627 MED 5.4 cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabiliti 0.6%
CVE-2022-22009 HIGH 7.8 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 0.6%
CVE-2022-21981 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.6%
CVE-2020-3486 MED 6.5 cisco ios_xe Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of 0.6%
CVE-2020-5876 HIGH 8.1 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur wh 0.6%
CVE-2018-0701 HIGH 8.8 bluestacks bluestacks BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass access restriction to gain unauthorized access. 0.6%
CVE-2017-2342 HIGH 8.1 juniper junos MACsec feature on Juniper Networks Junos OS 15.1X49 prior to 15.1X49-D100 on SRX300 series does not report errors when a secure link can not be established. It falls back to an unencrypted link. This can happen when MACsec is configured on ports that are not c 0.6%
CVE-2026-69502 CRIT 10.0 microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-69519 HIGH 8.6 microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2025-47979 MED 5.5 microsoft windows_server_2022_23h2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. 0.6%