IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-35431 CRIT 10.0 microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. 0.9% —
CVE-2026-33107 CRIT 10.0 microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-33105 CRIT 10.0 microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-32213 CRIT 10.0 microsoft azure_ai_foundry Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-32186 CRIT 10.0 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-32169 CRIT 10.0 microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-23907 MED 5.3 apache pdfbox-examples This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComp 0.9% —
CVE-2026-22828 HIGH 8.1 fortinet fortianalyzer_cloud A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successf 0.9% —
CVE-2024-49087 MED 4.6 microsoft windows_10_1809 Windows Mobile Broadband Driver Information Disclosure Vulnerability 0.9% —
CVE-2023-50740 MED 5.3 apache linkis In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users upgrade the version of Linkis to version 1.5.0 0.9% —
CVE-2023-20896 MED 5.9 vmware vcenter_server The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to deni 0.9% —
CVE-2022-35846 HIGH 8.1 fortinet fortitester An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a 0.9% —
CVE-2021-43081 MED 6.1 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may 0.9% —
CVE-2020-17070 HIGH 7.8 microsoft windows_10 Windows Update Medic Service Elevation of Privilege Vulnerability 0.9% —
CVE-2020-1584 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authentica 0.9% —
CVE-2020-1529 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then inst 0.9% —
CVE-2020-1520 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory. An attacker who successfully exploited the vulnerability would gain execution on a victim system. The security update addresses the vulnerability by corre 0.9% —
CVE-2020-1480 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then inst 0.9% —
CVE-2020-1479 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet 0.9% —
CVE-2020-1429 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. 0.9% —
CVE-2018-2021 MED 6.1 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. 0.9% —
CVE-2012-6396 MED 4.9 cisco nexus_7000 Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow remote authenticated users to cause a denial of service (memory consumption) via a crafted configuration that references interfaces that do not 0.9% —
CVE-2026-91006 HIGH 8.8 apache karaf Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into 0.9% —
CVE-2023-29326 HIGH 7.8 microsoft .net_framework .NET Framework Remote Code Execution Vulnerability 0.9% —
CVE-2022-36123 HIGH 7.8 linux linux_kernel The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges. 0.9% —