58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16981 | MED 6.1 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-70570 | HIGH 7.5 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.7% | — |
| CVE-2026-62183 | CRIT 9.8 | apache syncope Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration | 0.7% | — |
| CVE-2026-58595 | HIGH 8.1 | microsoft bing_search Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-46455 | CRIT 9.8 | apache camel Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and | 0.7% | — |
| CVE-2026-40701 | MED 4.8 | f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With thi | 0.7% | — |
| CVE-2026-34884 | CRIT 9.8 | apache skywalking_mcp SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | 0.7% | — |
| CVE-2026-28812 | CRIT 9.8 | apache jspwiki UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue. | 0.7% | — |
| CVE-2026-24014 | CRIT 9.8 | apache iotdb Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path | 0.7% | — |
| CVE-2024-35971 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Handle softirqs at the end of IRQ thread to fix hang The ks8851_irq() thread may call ks8851_rx_pkts() in case there are any packets in the MAC FIFO, which calls netif_rx(). Thi | 0.7% | — |
| CVE-2022-38039 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-37990 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26503 | HIGH 7.8 | veeam veeam Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges. | 0.7% | — |
| CVE-2021-47307 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses- | 0.7% | — |
| CVE-2021-47109 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will | 0.7% | — |
| CVE-2021-22051 | MED 6.5 | vmware spring_cloud_gateway Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users | 0.7% | — |
| CVE-2020-1667 | HIGH 8.3 | juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process might be bypassed due to a race con | 0.7% | — |
| CVE-2019-5443 | HIGH 7.8 | haxx curl A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user i | 0.7% | — |
| CVE-2013-1929 | MED 4.4 | linux linux_kernel Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted fir | 0.7% | — |
| CVE-2026-47296 | HIGH 7.5 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-24063 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-22040 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition between session setup and ksmbd_sessions_deregister. The session can be freed before the connection is | 0.7% | — |
| CVE-2022-26386 | MED 6.5 | mozilla firefox_esr Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was re | 0.7% | — |
| CVE-2022-0798 | HIGH 8.8 | google chrome Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | 0.7% | — |
| CVE-2021-32399 | HIGH 7.0 | debian debian_linux net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. | 0.7% | — |