57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70339 | MED 5.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.2% | — |
| CVE-2026-65804 | MED 6.1 | microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-63649 | ND | The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitel | 0.2% | — |
| CVE-2026-62828 | MED 5.4 | microsoft edge Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | 0.2% | — |
| CVE-2026-59841 | HIGH 7.5 | fortinet fortisiem A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here> | 0.2% | — |
| CVE-2026-58638 | MED 6.0 | microsoft windows_10_1809 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | 0.2% | — |
| CVE-2026-48349 | HIGH 8.1 | adobe animate Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user inte | 0.2% | — |
| CVE-2026-46320 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the | 0.2% | — |
| CVE-2026-40698 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege esca | 0.2% | — |
| CVE-2026-40061 | HIGH 8.7 | f5 big-ip_domain_name_system When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with | 0.2% | — |
| CVE-2026-32673 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c | 0.2% | — |
| CVE-2026-20149 | MED 6.1 | cisco webex A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed. This vulnerability was due to improper filtering | 0.2% | — |
| CVE-2025-66614 | CRIT 9.1 | apache tomcat Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be aff | 0.2% | — |
| CVE-2025-59999 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the API Access Profiles page that, when visited by another user, enables the attac | 0.2% | — |
| CVE-2025-59989 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker | 0.2% | — |
| CVE-2025-47890 | LOW 2.6 | fortinet fortios An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, For | 0.2% | — |
| CVE-2025-40325 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning a discard bio which has REQ_NOWAIT. And there is no need t | 0.2% | — |
| CVE-2025-39726 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time. | 0.2% | — |
| CVE-2025-38377 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: rose: fix dangling neighbour pointers in rose_rt_device_down() There are two bugs in rose_rt_device_down() that can cause use-after-free: 1. The loop bound `t->count` is modified within the | 0.2% | — |
| CVE-2025-21905 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: limit printed string from FW file There's no guarantee here that the file is always with a NUL-termination, so reading the string may read beyond the end of the TLV. If that's | 0.2% | — |
| CVE-2025-21862 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix incorrect initialization order Syzkaller reports the following bug: BUG: spinlock bad magic on CPU#1, syz-executor.0/7995 lock: 0xffff88805303f3e0, .magic: 00000000, .own | 0.2% | — |
| CVE-2025-21842 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt bo is declared as void amdgpu_amdkfd_free_gtt_mem(struct amdgpu_device *adev, void **mem_obj); Which | 0.2% | — |
| CVE-2025-21779 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-kernel Advertise support for Hyper-V's SEND_IPI and SEND_IPI_EX hypercalls if and only if the local API is emulated/virt | 0.2% | — |
| CVE-2025-20291 | MED 4.3 | cisco webex_meetings A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer actio | 0.2% | — |
| CVE-2024-8688 | MED 4.4 | paloaltonetworks pan-os An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewa | 0.2% | — |