58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43464 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_tail( | 0.7% | — |
| CVE-2026-41636 | HIGH 7.5 | apache thrift Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.7% | — |
| CVE-2026-40920 | CRIT 9.8 | apache ranger Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.7% | — |
| CVE-2025-21257 | MED 5.5 | microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-43626 | HIGH 7.8 | microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30041 | MED 5.4 | microsoft bing_search Microsoft Bing Search Spoofing Vulnerability | 0.7% | — |
| CVE-2023-27727 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | 0.7% | — |
| CVE-2022-22229 | HIGH 8.4 | juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv | 0.7% | — |
| CVE-2022-0023 | MED 5.9 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta | 0.7% | — |
| CVE-2021-41343 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-41336 | MED 5.5 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40475 | MED 5.5 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40472 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40468 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-38663 | MED 5.5 | microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-26430 | MED 6.0 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 0.7% | — |
| CVE-2020-2044 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track oper | 0.7% | — |
| CVE-2020-2043 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the | 0.7% | — |
| CVE-2019-20357 | HIGH 7.8 | trendmicro antivirus_\+_security_2019 A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain | 0.7% | — |
| CVE-2013-0160 | LOW 2.1 | linux linux_kernel The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. | 0.7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-52067 | MED 4.9 | apache nifi Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for | 0.7% | — |
| CVE-2024-42152 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin con | 0.7% | — |
| CVE-2024-36916 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behav | 0.7% | — |
| CVE-2024-28903 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |