58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-66906 | CRIT 9.1 | apache camel Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Az | 0.5% | — |
| CVE-2026-68789 | CRIT 9.9 | microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-62787 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows DNS allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-8635 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. | 0.5% | — |
| CVE-2026-8056 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function. | 0.5% | — |
| CVE-2025-66171 | MED 6.5 | apache cloudstack The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs us | 0.5% | — |
| CVE-2025-55675 | MED 6.5 | apache superset Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the dataso | 0.5% | — |
| CVE-2025-29978 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-21766 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear. | 0.5% | — |
| CVE-2023-37937 | HIGH 7.8 | fortinet fortiswitch An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows | 0.5% | — |
| CVE-2024-46717 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix incorrect page release Under the following conditions: 1) No skb created yet 2) header_size == 0 (no SHAMPO header) 3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PA | 0.5% | — |
| CVE-2023-36725 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-22302 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to th | 0.5% | — |
| CVE-2022-41114 | HIGH 7.0 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-24486 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-23008 | MED 5.4 | f5 nginx_controller_api_management On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data | 0.5% | — |
| CVE-2021-43248 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-43245 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-43223 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2020-5943 | MED 6.5 | f5 big-ip_access_policy_manager In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One example of protected | 0.5% | — |
| CVE-2020-5938 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would otherwise allow. | 0.5% | — |
| CVE-2018-16862 | MED 5.3 | canonical ubuntu_linux A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of | 0.5% | — |
| CVE-2018-10883 | MED 4.8 | canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image. | 0.5% | — |
| CVE-2017-3742 | MED 4.8 | lenovo connect2 In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable locati | 0.5% | — |
| CVE-2012-6657 | MED 4.9 | linux linux_kernel The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to creat | 0.5% | — |