IT
58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.586 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-52844 HIGH 7.5 caddyserver caddy Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenti 0.6% —
CVE-2025-21844 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent nu 0.6% —
CVE-2025-0103 HIGH 8.8 paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers 0.6% —
CVE-2024-47504 HIGH 7.5 juniper junos An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). When a non-clustered SRX500 0.6% —
CVE-2024-29008 MED 6.4 apache cloudstack A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM conf 0.6% —
CVE-2023-40714 CRIT 9.9 fortinet fortisiem A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements 0.6% —
CVE-2023-20215 MED 5.8 cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability i 0.6% —
CVE-2022-38022 LOW 3.3 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6% —
CVE-2021-29770 MED 6.5 ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. 0.6% —
CVE-2019-3016 MED 6.2 linux linux_kernel In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later 0.6% —
CVE-2019-19231 HIGH 7.3 broadcom ca_client_automation An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges. 0.6% —
CVE-2019-1235 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'. 0.6% —
CVE-2026-57105 HIGH 8.0 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-26929 MED 6.5 apache airflow Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not a 0.6% —
CVE-2025-29977 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6% —
CVE-2024-53240 MED 5.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash 0.6% —
CVE-2014-4632 MED 4.3 vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which 0.6% —
CVE-2012-6533 MED 4.4 symantec encryption_desktop Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application. 0.6% —
CVE-2026-25903 MED 6.6 apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi 0.6% —
CVE-2026-0287 HIGH 7.5 paloaltonetworks cloud_ngfw Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interfac 0.6% —
CVE-2025-64657 CRIT 9.8 microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. 0.6% —
CVE-2025-64656 CRIT 9.4 microsoft azure_application_gateway Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. 0.6% —
CVE-2025-47969 MED 4.4 microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. 0.6% —
CVE-2024-43536 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.6% —
CVE-2024-40591 HIGH 8.8 fortinet fortios An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their priv 0.6% —