IT
58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.646 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-33171 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7% —
CVE-2023-28314 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7% —
CVE-2023-21753 MED 5.5 microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability 0.7% —
CVE-2022-48658 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context. Commit 5a836bf6b09f ("mm: slub: move flush_cpu_slab() invocations __free_slab() invocations out of IRQ context") mov 0.7% —
CVE-2022-31663 MED 6.1 vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in t 0.7% —
CVE-2022-21867 HIGH 7.0 microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability 0.7% —
CVE-2022-21863 HIGH 7.0 microsoft windows_10 Windows StateRepository API Server file Elevation of Privilege Vulnerability 0.7% —
CVE-2020-16983 MED 5.7 microsoft azure_sphere Azure Sphere Tampering Vulnerability 0.7% —
CVE-2014-7970 MED 5.5 canonical ubuntu_linux The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both argumen 0.7% —
CVE-2011-0562 MED 6.9 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than 0.7% —
CVE-2009-1914 MED 4.9 linux linux_kernel The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers 0.7% —
CVE-2026-65113 CRIT 9.8 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and informati 0.7% —
CVE-2026-33791 MED 6.7 juniper junos An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete co 0.7% —
CVE-2026-24713 CRIT 9.8 apache iotdb Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. 0.7% —
CVE-2025-53763 CRIT 9.8 microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7% —
CVE-2025-30675 MED 4.7 apache cloudstack In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecu 0.7% —
CVE-2025-26634 HIGH 7.5 microsoft windows_10_1507 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2024-29994 HIGH 7.8 microsoft windows_10_1809 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability 0.7% —
CVE-2024-28901 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.7% —
CVE-2024-28900 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.7% —
CVE-2023-44159 HIGH 7.5 acronis cyber_protect Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. 0.7% —
CVE-2023-3389 HIGH 7.8 canonical ubuntu_linux A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac 0.7% —
CVE-2023-23421 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.7% —
CVE-2022-49075 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix qgroup reserve overflow the qgroup limit We use extent_changeset->bytes_changed in qgroup_reserve_data() to record how many bytes we set for EXTENT_QGROUP_RESERVED state. Currentl 0.7% —
CVE-2021-36188 MED 6.1 fortinet fortiweb A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and e 0.7% —