IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-70091 MED 5.9 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. 0.7% —
CVE-2026-32966 CRIT 9.8 apache dolphinscheduler DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0.7% —
CVE-2026-32226 MED 5.9 microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. 0.7% —
CVE-2026-24212 HIGH 7.5 nvidia isaac_launchable NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. 0.7% —
CVE-2025-68438 HIGH 7.5 apache airflow In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a se 0.7% —
CVE-2025-29837 MED 5.5 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. 0.7% —
CVE-2024-43501 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2024-29061 HIGH 7.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7% —
CVE-2023-32037 MED 6.5 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability 0.7% —
CVE-2022-49362 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix potential use-after-free in nfsd_file_put() nfsd_file_put_noref() can free @nf, so don't dereference @nf immediately upon return from nfsd_file_put_noref(). 0.7% —
CVE-2022-35795 HIGH 7.8 microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.7% —
CVE-2020-2013 HIGH 8.3 paloaltonetworks pan-os A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall wi 0.7% —
CVE-2019-15213 MED 4.6 linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. 0.7% —
CVE-2026-50485 MED 4.5 microsoft windows_10_1607 Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. 0.7% —
CVE-2026-42588 HIGH 8.1 apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console 0.7% —
CVE-2026-35194 HIGH 8.1 apache flink Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affec 0.7% —
CVE-2026-24640 MED 6.6 fortinet fortiweb A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated att 0.7% —
CVE-2025-49695 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7% —
CVE-2025-27531 CRIT 9.8 apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended t 0.7% —
CVE-2024-30363 MED 5.5 foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this 0.7% —
CVE-2023-2313 HIGH 8.8 google chrome Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) 0.7% —
CVE-2023-20192 CRIT 9.6 cisco telepresence_video_communication_server Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write creden 0.7% —
CVE-2022-41334 HIGH 8.8 fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of 0.7% —
CVE-2022-21928 MED 6.3 microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7% —
CVE-2022-21868 HIGH 7.0 microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability 0.7% —