58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-55814 | HIGH 7.5 | apache ranger Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.7% | — |
| CVE-2026-32690 | LOW 3.7 | apache airflow Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not a | 0.7% | — |
| CVE-2026-28814 | HIGH 7.5 | apache jspwiki Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. | 0.7% | — |
| CVE-2025-62458 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-54911 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-39534 | MED 5.4 | juniper junos_os_evolved An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the | 0.7% | — |
| CVE-2024-38084 | HIGH 7.8 | microsoft officeplus Microsoft OfficePlus Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-37985 | MED 5.9 | microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-36913 | CRIT 9.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that a | 0.7% | — |
| CVE-2024-23668 | HIGH 8.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.7% | — |
| CVE-2023-38163 | HIGH 7.8 | microsoft windows_defender_security_intelligence_updates Windows Defender Attack Surface Reduction Security Feature Bypass | 0.7% | — |
| CVE-2023-32020 | MED 5.6 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.7% | — |
| CVE-2023-23390 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23378 | HIGH 7.8 | microsoft print_3d Print 3D Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-26120 | MED 5.4 | fortinet fortiadc Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or | 0.7% | — |
| CVE-2021-1698 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-15270 | MED 5.4 | cisco firepower_management_center_firmware A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabil | 0.7% | — |
| CVE-2012-1326 | HIGH 7.4 | cisco ironport_web_security_appliance Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks | 0.7% | — |
| CVE-2026-34689 | HIGH 8.6 | adobe connect Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories o | 0.7% | — |
| CVE-2026-23570 | MED 6.5 | teamviewer digital_employee_experience A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sy | 0.7% | — |
| CVE-2025-62553 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-59271 | HIGH 8.7 | microsoft azure_cache_for_redis Redis Enterprise Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-47164 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-47489 | MED 5.8 | juniper junos_os_evolved An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cau | 0.7% | — |
| CVE-2023-36711 | HIGH 7.8 | microsoft windows_10_1507 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | 0.7% | — |