58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6597 | HIGH 7.8 | cisco firepower_extensible_operating_system A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform | 0.8% | — |
| CVE-2014-0077 | MED 5.5 | linux linux_kernel drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges o | 0.8% | — |
| CVE-2010-1940 | MED 4.3 | apple safari Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP | 0.8% | — |
| CVE-2004-1073 | LOW 2.1 | linux linux_kernel The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality. | 0.8% | — |
| CVE-2026-49298 | HIGH 8.8 | apache airflow A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes re | 0.8% | — |
| CVE-2026-45644 | HIGH 8.0 | microsoft live_share_canvas Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-43869 | HIGH 7.3 | apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.8% | — |
| CVE-2025-55526 | CRIT 9.1 | n8n fastapi n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py | 0.8% | — |
| CVE-2025-49713 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-45193 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 268759. | 0.8% | — |
| CVE-2023-23837 | HIGH 7.5 | solarwinds database_performance_analyzer No exception handling vulnerability which revealed sensitive or excessive information to users. | 0.8% | — |
| CVE-2021-22025 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to exis | 0.8% | — |
| CVE-2019-1380 | HIGH 7.8 | microsoft windows_10 A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2009-0783 | MED 4.2 | apache tomcat Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files | 0.8% | — |
| CVE-2026-68979 | CRIT 9.8 | apache nifi Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing compo | 0.8% | — |
| CVE-2026-66907 | HIGH 7.5 | apache camel Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud Stor | 0.8% | — |
| CVE-2026-63043 | HIGH 7.5 | apache inlong Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [ | 0.8% | — |
| CVE-2026-61372 | HIGH 7.5 | apache jena_fuseki Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. | 0.8% | — |
| CVE-2026-47896 | HIGH 7.5 | apache lucene.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recomm | 0.8% | — |
| CVE-2025-49740 | HIGH 8.8 | microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2023-20259 | HIGH 8.6 | cisco emergency_responder A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call proce | 0.8% | — |
| CVE-2021-31961 | MED 6.1 | microsoft windows_10 Windows InstallService Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-5935 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performi | 0.8% | — |
| CVE-2020-5854 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made. | 0.8% | — |
| CVE-2019-1647 | HIGH 8.0 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected | 0.8% | — |