IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-44914 HIGH 7.2 apache nifi Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required 0.7% —
CVE-2026-21529 MED 5.7 microsoft azure_hdinsight Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. 0.7% —
CVE-2024-53868 HIGH 7.5 apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes t 0.7% —
CVE-2024-53066 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs: Fix KMSAN warning in decode_getfattr_attrs() Fix the following KMSAN warning: CPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B Tainted: [B]=BAD_PAGE Hardware name: QEMU Standard PC (Q3 0.7% —
CVE-2024-30471 LOW 3.7 apache streampipes Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, 0.7% —
CVE-2023-20866 MED 6.5 vmware spring_session In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application i 0.7% —
CVE-2022-45431 HIGH 7.5 dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart o 0.7% —
CVE-2022-27502 HIGH 7.8 realvnc vnc_server RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. 0.7% —
CVE-2022-22157 HIGH 7.2 juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on 0.7% —
CVE-2022-21869 HIGH 7.0 microsoft windows_10 Clipboard User Service Elevation of Privilege Vulnerability 0.7% —
CVE-2022-21861 HIGH 7.0 microsoft windows_10 Task Flow Data Engine Elevation of Privilege Vulnerability 0.7% —
CVE-2021-22543 HIGH 7.8 debian debian_linux An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to r 0.7% —
CVE-2018-0324 MED 6.7 cisco network_functions_virtualization_infrastructure A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command paramet 0.7% —
CVE-2016-4928 HIGH 8.8 juniper junos_space Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space. 0.7% —
CVE-2026-20943 HIGH 7.0 microsoft office Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7% —
CVE-2025-21347 MED 6.0 microsoft windows_10_1507 Windows Deployment Services Denial of Service Vulnerability 0.7% —
CVE-2024-38612 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist 0.7% —
CVE-2024-20330 HIGH 8.6 cisco secure_firewall_threat_defense A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause th 0.7% —
CVE-2023-52513 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case immediate MPA request processing fails, the newly created endpoint unlinks the listening endpoint and is ready to be dropped. This special c 0.7% —
CVE-2023-2316 HIGH 7.4 typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma 0.7% —
CVE-2022-32414 MED 5.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c. 0.7% —
CVE-2022-31307 MED 5.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c. 0.7% —
CVE-2022-31306 MED 5.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. 0.7% —
CVE-2021-31364 MED 5.9 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated networ 0.7% —
CVE-2020-8648 HIGH 7.1 broadcom brocade_fabric_operating_system_firmware There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. 0.7% —