IT
58.564 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.564 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-42990 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. 1.0% —
CVE-2026-41096 CRIT 9.8 microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. 1.0% —
CVE-2026-41089 CRIT 9.8 microsoft windows_server_2012 Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. 1.0% —
CVE-2026-40412 CRIT 10.0 microsoft azure_orbital_spatio Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. 1.0% —
CVE-2025-58717 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2025-55700 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2025-49758 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.0% —
CVE-2023-52699 MED 5.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointe 1.0% —
CVE-2021-34766 MED 5.4 cisco smart_software_manager_on-prem A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to 1.0% —
CVE-2021-33760 MED 5.5 microsoft windows_10 Media Foundation Information Disclosure Vulnerability 1.0% —
CVE-2021-20508 MED 4.3 ibm security_secret_server IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322 1.0% —
CVE-2020-26079 MED 4.9 cisco iot_field_network_director A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker 1.0% —
CVE-2019-1904 HIGH 8.8 cisco ios_xe A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the 1.0% —
CVE-2019-0659 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. 1.0% —
CVE-2014-0736 MED 6.8 cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of arbitrary users for re 1.0% —
CVE-2026-85917 HIGH 7.5 microsoft foundry Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 1.0% —
CVE-2026-69558 HIGH 8.6 microsoft partner_center Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-66800 HIGH 8.6 microsoft azure_data_factory Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-66304 HIGH 7.5 microsoft skype_for_business_server Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-62835 CRIT 9.3 microsoft azure_portal Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 1.0% —
CVE-2024-54181 HIGH 7.2 ibm websphere_automation IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system. 1.0% —
CVE-2024-26592 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_transport` in ksmbd_tcp_new_ 1.0% —
CVE-2023-28283 HIGH 8.1 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.0% —
CVE-2022-29121 MED 6.5 microsoft windows_10 Windows WLAN AutoConfig Service Denial of Service Vulnerability 1.0% —