58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62916 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-58630 | CRIT 10.0 | microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-42782 | HIGH 7.2 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class sta | 0.9% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-30314 | HIGH 7.8 | adobe dreamweaver Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue doe | 0.9% | — |
| CVE-2023-51650 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Versi | 0.9% | — |
| CVE-2023-50380 | MED 6.5 | apache ambari XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege esc | 0.9% | — |
| CVE-2022-29134 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-29127 | MED 4.2 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2022-29123 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-29122 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-26930 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-25108 | MED 5.5 | foxit pdf_editor Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation. | 0.9% | — |
| CVE-2022-22011 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-44168 | LOW 3.3 | fortinet fortios A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages. | 0.9% | |
| CVE-2021-42299 | MED 5.6 | microsoft surface_pro_3_firmware Microsoft Surface Pro 3 Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2018-17039 | MED 6.1 | 1234n minicms MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled. | 0.9% | — |
| CVE-2018-0363 | HIGH 8.8 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary acti | 0.9% | — |
| CVE-2017-5074 | HIGH 8.0 | google chrome A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth. | 0.9% | — |
| CVE-2016-4558 | HIGH 7.0 | canonical ubuntu_linux The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of m | 0.9% | — |
| CVE-2026-41284 | HIGH 7.5 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affec | 0.9% | — |
| CVE-2024-32760 | MED 6.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. | 0.9% | — |
| CVE-2023-36696 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1411 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1336. | 0.9% | — |
| CVE-2020-1406 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows Network List Service Elevation of Privilege Vulnerability'. | 0.9% | — |