IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-8859 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl 0.6%
CVE-2026-7667 HIGH 8.8 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary fi 0.6%
CVE-2026-10817 HIGH 7.5 citrix netscaler_application_delivery_controller Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler 0.6%
CVE-2026-41043 MED 6.5 apache activemq Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to 0.6%
CVE-2026-23450 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softir 0.6%
CVE-2022-49770 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it' 0.6%
CVE-2025-27867 MED 5.6 apache felix_http_webconsole_plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrad 0.6%
CVE-2025-22222 HIGH 7.7 vmware aria_operations VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. 0.6%
CVE-2024-20695 MED 5.7 microsoft skype_for_business_server Skype for Business Information Disclosure Vulnerability 0.6%
CVE-2022-23255 MED 5.9 microsoft onedrive Microsoft OneDrive for Android Security Feature Bypass Vulnerability 0.6%
CVE-2019-15923 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c. 0.6%
CVE-2018-0029 MED 5.7 juniper junos While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both singl 0.6%
CVE-2010-0727 MED 4.9 debian debian_linux The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission 0.6%
CVE-2026-47634 HIGH 7.3 microsoft sharepoint_server Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2026-41615 CRIT 9.6 microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-26120 MED 6.5 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. 0.6%
CVE-2026-0386 HIGH 7.5 microsoft windows_server_2008 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. 0.6%
CVE-2025-33074 HIGH 7.5 microsoft azure_functions Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. 0.6%
CVE-2024-45478 MED 4.8 apache ranger Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. 0.6%
CVE-2024-8534 HIGH 8.1 citrix netscaler_application_delivery_controller Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) a 0.6%
CVE-2024-50154 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ We are seeing a use-after-free from a bpf prog at 0.6%
CVE-2023-40250 HIGH 8.8 hancom hcell Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893. 0.6%
CVE-2023-20246 MED 5.8 cisco ios_xe Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs wh 0.6%
CVE-2023-27875 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. 0.6%
CVE-2022-41329 MED 5.3 fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to 0.6%