58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-65128 | HIGH 8.8 | nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | 0.7% | — |
| CVE-2026-62882 | MED 4.3 | microsoft 365_apps Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-20838 | MED 5.5 | microsoft windows_11_23h2 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20827 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20823 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-50169 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2024-35797 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in | 0.7% | — |
| CVE-2024-23590 | CRIT 9.1 | apache kylin Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue. | 0.7% | — |
| CVE-2023-34056 | MED 4.3 | vmware vcenter_server vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. | 0.7% | — |
| CVE-2022-45797 | HIGH 7.1 | trendmicro apex_one An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an att | 0.7% | — |
| CVE-2022-23293 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-20916 | MED 6.1 | cisco iot_control_center A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based ma | 0.7% | — |
| CVE-2019-1565 | MED 5.4 | paloaltonetworks pan-os The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to in | 0.7% | — |
| CVE-2026-42527 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' | 0.7% | — |
| CVE-2026-31378 | MED 6.5 | apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.7% | — |
| CVE-2026-24266 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |
| CVE-2024-41783 | CRIT 9.1 | ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input. | 0.7% | — |
| CVE-2024-20459 | MED 6.5 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying op | 0.7% | — |
| CVE-2023-32016 | MED 5.5 | microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-29341 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29340 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24905 | HIGH 7.8 | microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-22285 | HIGH 7.5 | intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2023-20270 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies | 0.7% | — |
| CVE-2022-20691 | MED 5.3 | cisco ata_190_firmware A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerability is due to missing l | 0.7% | — |