IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-65128 HIGH 8.8 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. 0.7% —
CVE-2026-62882 MED 4.3 microsoft 365_apps Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 0.7% —
CVE-2026-20838 MED 5.5 microsoft windows_11_23h2 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. 0.7% —
CVE-2026-20827 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. 0.7% —
CVE-2026-20823 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.7% —
CVE-2025-50169 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2024-35797 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in 0.7% —
CVE-2024-23590 CRIT 9.1 apache kylin Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue. 0.7% —
CVE-2023-34056 MED 4.3 vmware vcenter_server vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. 0.7% —
CVE-2022-45797 HIGH 7.1 trendmicro apex_one An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an att 0.7% —
CVE-2022-23293 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2022-20916 MED 6.1 cisco iot_control_center A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based ma 0.7% —
CVE-2019-1565 MED 5.4 paloaltonetworks pan-os The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to in 0.7% —
CVE-2026-42527 HIGH 8.1 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' 0.7% —
CVE-2026-31378 MED 6.5 apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.7% —
CVE-2026-24266 MED 5.9 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. 0.7% —
CVE-2024-41783 CRIT 9.1 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input. 0.7% —
CVE-2024-20459 MED 6.5 cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying op 0.7% —
CVE-2023-32016 MED 5.5 microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability 0.7% —
CVE-2023-29341 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0.7% —
CVE-2023-29340 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0.7% —
CVE-2023-24905 HIGH 7.8 microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability 0.7% —
CVE-2023-22285 HIGH 7.5 intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. 0.7% —
CVE-2023-20270 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies 0.7% —
CVE-2022-20691 MED 5.3 cisco ata_190_firmware A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerability is due to missing l 0.7% —