58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-59118 | CRIT 9.3 | microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-63796 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors ocfs2_validate_gd_parent() only bounds bg_bits against the parent allocator's chain geometry. A malicious descriptor can still claim a bg_si | 0.5% | — |
| CVE-2026-50661 | MED 6.1 | microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2026-11944 | MED 6.5 | os4ed opensis openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences. | 0.5% | — |
| CVE-2026-43208 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption that the RPS table for each receive queue would have the same size, and that it would not change. Compute flow_id | 0.5% | — |
| CVE-2026-0102 | LOW 3.1 | microsoft edge_chromium Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number | 0.5% | — |
| CVE-2025-64785 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the appl | 0.5% | — |
| CVE-2025-55229 | MED 5.3 | microsoft windows_10_1507 Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-33121 | HIGH 7.1 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | 0.5% | — |
| CVE-2023-53083 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's | 0.5% | — |
| CVE-2024-50152 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/client/smb2ops.c:1304:2: Attempt to free released memory. 1304 | kfree(ea); | 0.5% | — |
| CVE-2024-41727 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical | 0.5% | — |
| CVE-2024-39778 | HIGH 7.5 | f5 big-ip_access_policy_manager When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2023-48789 | MED 4.3 | fortinet fortiportal A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests. | 0.5% | — |
| CVE-2024-21402 | HIGH 7.1 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-22386 | MED 5.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information | 0.5% | — |
| CVE-2022-22377 | MED 5.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information | 0.5% | — |
| CVE-2023-41680 | HIGH 7.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3 | 0.5% | — |
| CVE-2023-20104 | MED 6.1 | cisco webex_teams A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of | 0.5% | — |
| CVE-2023-21726 | HIGH 7.8 | microsoft windows_10_1607 Windows Credential Manager User Interface Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35851 | HIGH 8.0 | fortinet fortiadc An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted | 0.5% | — |
| CVE-2021-39015 | MED 5.4 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr | 0.5% | — |
| CVE-2021-23026 | HIGH 8.8 | f5 big-ip_access_policy_manager BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through | 0.5% | — |
| CVE-2021-1476 | MED 6.7 | cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected d | 0.5% | — |
| CVE-2019-19954 | HIGH 7.3 | signal signal-desktop Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. | 0.5% | — |