57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-8859 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl | 0.6% | — |
| CVE-2026-7667 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary fi | 0.6% | — |
| CVE-2026-10817 | HIGH 7.5 | citrix netscaler_application_delivery_controller Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | 0.6% | — |
| CVE-2026-41043 | MED 6.5 | apache activemq Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to | 0.6% | — |
| CVE-2026-23450 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softir | 0.6% | — |
| CVE-2022-49770 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it' | 0.6% | — |
| CVE-2025-27867 | MED 5.6 | apache felix_http_webconsole_plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrad | 0.6% | — |
| CVE-2025-22222 | HIGH 7.7 | vmware aria_operations VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. | 0.6% | — |
| CVE-2024-20695 | MED 5.7 | microsoft skype_for_business_server Skype for Business Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-23255 | MED 5.9 | microsoft onedrive Microsoft OneDrive for Android Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2019-15923 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c. | 0.6% | — |
| CVE-2018-0029 | MED 5.7 | juniper junos While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both singl | 0.6% | — |
| CVE-2010-0727 | MED 4.9 | debian debian_linux The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission | 0.6% | — |
| CVE-2026-47634 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-41615 | CRIT 9.6 | microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-26120 | MED 6.5 | microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. | 0.6% | — |
| CVE-2026-0386 | HIGH 7.5 | microsoft windows_server_2008 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2025-33074 | HIGH 7.5 | microsoft azure_functions Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2024-45478 | MED 4.8 | apache ranger Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | 0.6% | — |
| CVE-2024-8534 | HIGH 8.1 | citrix netscaler_application_delivery_controller Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) a | 0.6% | — |
| CVE-2024-50154 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ We are seeing a use-after-free from a bpf prog at | 0.6% | — |
| CVE-2023-40250 | HIGH 8.8 | hancom hcell Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893. | 0.6% | — |
| CVE-2023-20246 | MED 5.8 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs wh | 0.6% | — |
| CVE-2023-27875 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. | 0.6% | — |
| CVE-2022-41329 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to | 0.6% | — |