IT
58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-27315 MED 4.3 apache superset An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surf 1.0% —
CVE-2023-20562 HIGH 7.8 amd amd_uprof Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution. 1.0% —
CVE-2022-20730 MED 4.0 cisco secure_firewall_threat_defense A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processi 1.0% —
CVE-2021-1622 HIGH 8.6 cisco ios_xe A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This v 1.0% —
CVE-2020-1133 MED 5.5 microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp 1.0% —
CVE-2017-6356 MED 5.3 paloaltonetworks terminal_services_agent Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors. 1.0% —
CVE-2015-1451 LOW 3.5 fortinet fortios Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request. 1.0% —
CVE-2011-4850 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, 1.0% —
CVE-2026-82311 CRIT 9.8 apache apache-airflow-providers-fab Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's i 1.0% —
CVE-2026-76187 CRIT 9.8 apache apache-airflow-providers-keycloak Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authen 1.0% —
CVE-2026-55015 MED 5.5 microsoft remote_help Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. 1.0% —
CVE-2026-47298 HIGH 8.0 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.0% —
CVE-2023-36765 HIGH 7.8 microsoft office Microsoft Office Elevation of Privilege Vulnerability 1.0% —
CVE-2023-36590 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0% —
CVE-2023-36583 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0% —
CVE-2023-36582 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0% —
CVE-2023-36578 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0% —
CVE-2023-21751 MED 6.5 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 1.0% —
CVE-2022-35806 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 1.0% —
CVE-2022-35639 HIGH 7.5 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. 1.0% —
CVE-2021-31169 HIGH 7.8 microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability 1.0% —
CVE-2021-31168 HIGH 7.8 microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability 1.0% —
CVE-2021-31165 HIGH 7.8 microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability 1.0% —
CVE-2020-15706 MED 6.4 canonical ubuntu_linux GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restri 1.0% —
CVE-2020-1082 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vul 1.0% —