58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70091 | MED 5.9 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. | 0.7% | — |
| CVE-2026-32966 | CRIT 9.8 | apache dolphinscheduler DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.7% | — |
| CVE-2026-32226 | MED 5.9 | microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.7% | — |
| CVE-2026-24212 | HIGH 7.5 | nvidia isaac_launchable NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | 0.7% | — |
| CVE-2025-68438 | HIGH 7.5 | apache airflow In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a se | 0.7% | — |
| CVE-2025-29837 | MED 5.5 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2024-43501 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-29061 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2023-32037 | MED 6.5 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-49362 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix potential use-after-free in nfsd_file_put() nfsd_file_put_noref() can free @nf, so don't dereference @nf immediately upon return from nfsd_file_put_noref(). | 0.7% | — |
| CVE-2022-35795 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-2013 | HIGH 8.3 | paloaltonetworks pan-os A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall wi | 0.7% | — |
| CVE-2019-15213 | MED 4.6 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. | 0.7% | — |
| CVE-2026-50485 | MED 4.5 | microsoft windows_10_1607 Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0.7% | — |
| CVE-2026-42588 | HIGH 8.1 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console | 0.7% | — |
| CVE-2026-35194 | HIGH 8.1 | apache flink Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affec | 0.7% | — |
| CVE-2026-24640 | MED 6.6 | fortinet fortiweb A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated att | 0.7% | — |
| CVE-2025-49695 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-27531 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended t | 0.7% | — |
| CVE-2024-30363 | MED 5.5 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0.7% | — |
| CVE-2023-2313 | HIGH 8.8 | google chrome Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) | 0.7% | — |
| CVE-2023-20192 | CRIT 9.6 | cisco telepresence_video_communication_server Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write creden | 0.7% | — |
| CVE-2022-41334 | HIGH 8.8 | fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of | 0.7% | — |
| CVE-2022-21928 | MED 6.3 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21868 | HIGH 7.0 | microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability | 0.7% | — |