IT
58.575 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.575 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-36569 HIGH 8.4 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 0.6% —
CVE-2022-37979 HIGH 7.8 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0.6% —
CVE-2021-41020 HIGH 8.8 fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. 0.6% —
CVE-2021-24092 HIGH 7.8 microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability 0.6% —
CVE-2014-4700 MED 4.9 citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. 0.6% —
CVE-2012-5459 HIGH 7.9 vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." 0.6% —
CVE-2026-56188 CRIT 9.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0.6% —
CVE-2026-22068 HIGH 8.2 apache traffic_server Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. 0.6% —
CVE-2026-19297 CRIT 9.1 langflow langflow IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. 0.6% —
CVE-2025-21844 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent nu 0.6% —
CVE-2025-10226 CRIT 9.8 axxonsoft axxon_one Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via e 0.6% —
CVE-2024-53058 CRIT 9.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data In case the non-paged data of a SKB carries protocol header and protocol payload to be transmitted on a certain platform 0.6% —
CVE-2024-38218 HIGH 8.4 microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability 0.6% —
CVE-2023-21531 HIGH 7.0 microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability 0.6% —
CVE-2022-34690 HIGH 7.1 microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability 0.6% —
CVE-2022-22215 MED 6.5 juniper junos A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Ser 0.6% —
CVE-2022-20965 MED 4.3 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control 0.6% —
CVE-2021-22033 LOW 2.7 vmware cloud_foundation Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. 0.6% —
CVE-2017-9489 HIGH 8.8 cisco dpc3939b_firmware The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF. 0.6% —
CVE-2026-77898 HIGH 7.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-69607 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-69397 HIGH 7.5 microsoft windows_10_1809 Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-66315 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-59117 HIGH 7.5 microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. 0.6% —