IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2006-5757 LOW 1.2 linux linux_kernel Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data struct 0.8% —
CVE-2026-71559 HIGH 7.5 apache fory Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache F 0.8% —
CVE-2026-26120 MED 6.5 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. 0.8% —
CVE-2024-41048 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: skmsg: Skip zero length skb in sk_msg_recvmsg When running BPF selftests (./test_progs -t sockmap_basic) on a Loongarch platform, the following kernel panic occurs: [...] Oops[#1]: CP 0.8% —
CVE-2023-21567 MED 5.6 microsoft visual_studio_2017 Visual Studio Denial of Service Vulnerability 0.8% —
CVE-2022-31246 MED 5.5 electrum electrum paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data). On Windows, this can lead to capture of credentials over SMB. On Linux and UNIX, it can lead to a denial of service by specifyi 0.8% —
CVE-2022-23447 HIGH 7.5 fortinet fortiextender_firmware An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 throu 0.8% —
CVE-2017-7374 HIGH 7.8 linux linux_kernel Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing 0.8% —
CVE-2026-70340 HIGH 8.1 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69865 CRIT 10.0 microsoft azure_container_registry Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69555 CRIT 10.0 microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69502 CRIT 10.0 microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-65667 CRIT 10.0 microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-64878 CRIT 9.9 tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. 0.8% —
CVE-2026-63508 CRIT 10.0 microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-41613 HIGH 8.8 microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-41103 CRIT 9.1 microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-26111 HIGH 8.0 microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8% —
CVE-2024-45626 MED 6.5 apache james_server Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue. 0.8% —
CVE-2023-37931 HIGH 8.8 fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via se 0.8% —
CVE-2022-41051 HIGH 7.8 microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0.8% —
CVE-2022-30594 HIGH 7.8 debian debian_linux The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. 0.8% —
CVE-2022-22977 HIGH 7.1 vmware tools VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to 0.8% —
CVE-2022-20810 MED 6.5 cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient 0.8% —
CVE-2001-0161 MED 5.0 cisco aironet Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. 0.8% —