IT
58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-1227 HIGH 8.1 cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API 0.7% —
CVE-2020-3378 MED 4.3 cisco sd-wan_firmware A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient val 0.7% —
CVE-2026-57817 HIGH 8.1 apache cxf The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the 0.7% —
CVE-2026-49042 HIGH 7.3 apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue. 0.7% —
CVE-2026-47623 HIGH 8.2 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. 0.7% —
CVE-2026-46588 HIGH 7.3 apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue. 0.7% —
CVE-2026-46587 HIGH 7.3 apache camel Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue. 0.7% —
CVE-2025-29821 MED 5.5 microsoft dynamics_365_business_central_2023 Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. 0.7% —
CVE-2024-47250 MED 5.0 apache nimble Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluetooth 0.7% —
CVE-2024-38379 MED 4.8 apache allura Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted. This issue affects Apache Allu 0.7% —
CVE-2024-26217 MED 5.5 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.7% —
CVE-2024-24778 MED 6.5 apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe 0.7% —
CVE-2022-49048 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when forwarding a pkt with no in6 dev kongweibin reported a kernel panic in ip6_forward() when input interface has no in6 dev associated. The following tc commands were used 0.7% —
CVE-2022-38017 MED 6.8 microsoft storsimple_8010_firmware StorSimple 8000 Series Elevation of Privilege Vulnerability 0.7% —
CVE-2022-33681 MED 5.9 apache pulsar Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client to the Pulsar Broker/Proxy and connections from the Pulsar Proxy to the Pulsar B 0.7% —
CVE-2022-23181 HIGH 7.0 apache tomcat The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of t 0.7% —
CVE-2022-21858 HIGH 7.8 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.7% —
CVE-2022-21852 HIGH 7.8 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0.7% —
CVE-2021-43976 MED 4.6 debian debian_linux In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). 0.7% —
CVE-2021-39089 MED 4.3 ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387. 0.7% —
CVE-2021-26095 HIGH 7.5 fortinet fortimail The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to po 0.7% —
CVE-2019-19319 MED 6.5 linux linux_kernel In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, 0.7% —
CVE-2016-5001 MED 5.5 apache hadoop This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random 0.7% —
CVE-2004-0814 LOW 1.2 linux linux_kernel Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers t 0.7% —
CVE-2026-82428 HIGH 8.8 Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. Whe 0.7% —