IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-38565 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ar5523: enable proper endpoint verification Syzkaller reports [1] hitting a warning about an endpoint in use not having an expected type to it. Fix the issue by checking for the exist 0.7% —
CVE-2024-29062 HIGH 7.1 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7% —
CVE-2024-26851 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: Add protection for bmp length out of range UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts that are out of bounds for their data type. v 0.7% —
CVE-2024-26845 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to tmr_list handling An abort that is responded to by iSCSI itself is added to tmr_list but does not go to target core. A LUN_RESET that goes through tmr_list tak 0.7% —
CVE-2024-21753 MED 5.5 fortinet forticlient_endpoint_management_server A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker t 0.7% —
CVE-2022-43863 MED 6.7 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. 0.7% —
CVE-2021-26880 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.7% —
CVE-2021-26872 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.7% —
CVE-2021-26870 HIGH 7.8 microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability 0.7% —
CVE-2020-3462 MED 6.3 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-subm 0.7% —
CVE-2020-26064 HIGH 8.1 cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Enti 0.7% —
CVE-2020-11990 LOW 3.3 apache cordova We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access 0.7% —
CVE-2019-18568 HIGH 8.8 avira free_antivirus Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user. 0.7% —
CVE-2009-4914 HIGH 7.8 cisco asa_5580 Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879 0.7% —
CVE-2026-84501 MED 5.3 apache zookeeper An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvi 0.7% —
CVE-2026-84439 MED 5.3 apache zookeeper When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the aud 0.7% —
CVE-2026-69419 HIGH 8.5 microsoft azure_data_manager_for_energy Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-50505 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-50500 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-50340 HIGH 8.5 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-50076 CRIT 9.1 apache fory Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present r 0.7% —
CVE-2025-55672 MED 5.4 apache superset A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets execut 0.7% —
CVE-2025-49763 HIGH 7.5 apache traffic_server ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traf 0.7% —
CVE-2024-45217 HIGH 8.1 apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that 0.7% —
CVE-2024-43106 HIGH 7.1 microsoft excel A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger thi 0.7% —