IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-55814 HIGH 7.5 apache ranger Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.7% —
CVE-2026-32690 LOW 3.7 apache airflow Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not a 0.7% —
CVE-2026-28814 HIGH 7.5 apache jspwiki Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. 0.7% —
CVE-2025-62458 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.7% —
CVE-2025-54911 HIGH 7.3 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0.7% —
CVE-2024-39534 MED 5.4 juniper junos_os_evolved An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the 0.7% —
CVE-2024-38084 HIGH 7.8 microsoft officeplus Microsoft OfficePlus Elevation of Privilege Vulnerability 0.7% —
CVE-2024-37985 MED 5.9 microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability 0.7% —
CVE-2024-36913 CRIT 9.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that a 0.7% —
CVE-2024-23668 HIGH 8.8 fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL 0.7% —
CVE-2023-38163 HIGH 7.8 microsoft windows_defender_security_intelligence_updates Windows Defender Attack Surface Reduction Security Feature Bypass 0.7% —
CVE-2023-32020 MED 5.6 microsoft windows_server_2008 Windows DNS Spoofing Vulnerability 0.7% —
CVE-2023-23390 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7% —
CVE-2023-23378 HIGH 7.8 microsoft print_3d Print 3D Remote Code Execution Vulnerability 0.7% —
CVE-2022-26120 MED 5.4 fortinet fortiadc Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or 0.7% —
CVE-2021-1698 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 0.7% —
CVE-2019-15270 MED 5.4 cisco firepower_management_center_firmware A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabil 0.7% —
CVE-2012-1326 HIGH 7.4 cisco ironport_web_security_appliance Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks 0.7% —
CVE-2026-34689 HIGH 8.6 adobe connect Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories o 0.7% —
CVE-2026-23570 MED 6.5 teamviewer digital_employee_experience A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sy 0.7% —
CVE-2025-62553 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.7% —
CVE-2025-59271 HIGH 8.7 microsoft azure_cache_for_redis Redis Enterprise Elevation of Privilege Vulnerability 0.7% —
CVE-2025-47164 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7% —
CVE-2024-47489 MED 5.8 juniper junos_os_evolved An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cau 0.7% —
CVE-2023-36711 HIGH 7.8 microsoft windows_10_1507 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability 0.7% —