IT
58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.586 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2012-4072 MED 4.3 cisco unified_computing_system The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka 0.6% —
CVE-2026-66908 HIGH 7.5 apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe 0.6% —
CVE-2025-59282 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.6% —
CVE-2025-21184 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0.6% —
CVE-2024-56662 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] B 0.6% —
CVE-2024-38086 MED 6.4 microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability 0.6% —
CVE-2023-36719 HIGH 7.8 microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability 0.6% —
CVE-2023-36408 HIGH 7.8 microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability 0.6% —
CVE-2023-23482 MED 5.4 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim 0.6% —
CVE-2023-22637 MED 6.5 fortinet fortinac An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Mana 0.6% —
CVE-2022-44710 HIGH 7.8 microsoft windows_11 DirectX Graphics Kernel Elevation of Privilege Vulnerability 0.6% —
CVE-2022-42432 MED 4.4 linux linux_kernel This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerabi 0.6% —
CVE-2022-28874 MED 4.3 f-secure atlant Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploi 0.6% —
CVE-2022-23766 HIGH 7.8 bigfile bigfileagent An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a gene 0.6% —
CVE-2021-43064 MED 4.3 fortinet fortiweb A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers. 0.6% —
CVE-2021-3444 HIGH 7.8 canonical ubuntu_linux The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leadi 0.6% —
CVE-2020-3207 MED 6.7 cisco ios_xe A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. T 0.6% —
CVE-2026-65113 CRIT 9.8 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and informati 0.6% —
CVE-2026-59309 CRIT 9.8 vmware vcenter_server VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. 0.6% —
CVE-2026-29226 HIGH 7.3 apache ofbiz Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.6% —
CVE-2025-59390 CRIT 9.8 apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr 0.6% —
CVE-2025-47979 MED 5.5 microsoft windows_server_2022_23h2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. 0.6% —
CVE-2024-45720 HIGH 8.2 apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra 0.6% —
CVE-2024-28919 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6% —
CVE-2024-20669 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6% —