IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-43464 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_tail( 0.7% —
CVE-2026-41636 HIGH 7.5 apache thrift Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.7% —
CVE-2026-40920 CRIT 9.8 apache ranger Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.7% —
CVE-2025-21257 MED 5.5 microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability 0.7% —
CVE-2024-43626 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability 0.7% —
CVE-2024-30041 MED 5.4 microsoft bing_search Microsoft Bing Search Spoofing Vulnerability 0.7% —
CVE-2023-27727 HIGH 7.5 f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. 0.7% —
CVE-2022-22229 HIGH 8.4 juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv 0.7% —
CVE-2022-0023 MED 5.9 paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta 0.7% —
CVE-2021-41343 MED 5.5 microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability 0.7% —
CVE-2021-41336 MED 5.5 microsoft windows_11 Windows Kernel Information Disclosure Vulnerability 0.7% —
CVE-2021-40475 MED 5.5 microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability 0.7% —
CVE-2021-40472 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 0.7% —
CVE-2021-40468 MED 5.5 microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability 0.7% —
CVE-2021-38663 MED 5.5 microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability 0.7% —
CVE-2021-26430 MED 6.0 microsoft azure_sphere Azure Sphere Denial of Service Vulnerability 0.7% —
CVE-2020-2044 LOW 3.3 paloaltonetworks pan-os An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track oper 0.7% —
CVE-2020-2043 LOW 3.3 paloaltonetworks pan-os An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the 0.7% —
CVE-2019-20357 HIGH 7.8 trendmicro antivirus_\+_security_2019 A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain 0.7% —
CVE-2013-0160 LOW 2.1 linux linux_kernel The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. 0.7% —
CVE-2025-49746 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2024-52067 MED 4.9 apache nifi Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for 0.7% —
CVE-2024-42152 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin con 0.7% —
CVE-2024-36916 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behav 0.7% —
CVE-2024-28903 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7% —