58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.285 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50520 | HIGH 8.4 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-48589 | MED 5.4 | apache shiro Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in appli | 0.4% | — |
| CVE-2026-43514 | LOW 3.7 | apache tomcat Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 thr | 0.4% | — |
| CVE-2026-43112 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic | 0.4% | — |
| CVE-2026-41856 | HIGH 7.5 | vmware spring_for_graphql The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met | 0.4% | — |
| CVE-2026-40690 | MED 4.3 | apache airflow The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside | 0.4% | — |
| CVE-2026-38743 | MED 4.3 | apache airflow The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request paramet | 0.4% | — |
| CVE-2026-1642 | MED 5.9 | f5 nginx_gateway_fabric A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control | 0.4% | — |
| CVE-2026-11024 | HIGH 8.8 | google chrome Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2025-23329 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and accessing the shared memory region used by the Python backend. A successful exploit of this vulnerability might lea | 0.4% | — |
| CVE-2024-47422 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, whi | 0.4% | — |
| CVE-2024-45138 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m | 0.4% | — |
| CVE-2024-20305 | MED 4.8 | cisco unity_connection A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based manage | 0.4% | — |
| CVE-2023-47050 | MED 5.5 | adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln | 0.4% | — |
| CVE-2023-47049 | MED 5.5 | adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln | 0.4% | — |
| CVE-2023-47048 | MED 5.5 | adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln | 0.4% | — |
| CVE-2023-20179 | MED 4.3 | cisco sd-wan_vmanage A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content. This vulnerability is due to improper validation of user-supplied da | 0.4% | — |
| CVE-2022-44650 | HIGH 7.8 | trendmicro apex_one A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ab | 0.4% | — |
| CVE-2022-44649 | HIGH 7.8 | trendmicro apex_one An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain th | 0.4% | — |
| CVE-2022-26828 | HIGH 7.0 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2020-3996 | MED 5.5 | vmware velero Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users. | 0.4% | — |
| CVE-2020-3234 | HIGH 8.8 | cisco ios A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, l | 0.4% | — |
| CVE-2020-14390 | MED 5.6 | debian debian_linux A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled o | 0.4% | — |
| CVE-2019-1682 | HIGH 7.8 | cisco application_policy_infrastructure_controller A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerability is due to insuffici | 0.4% | — |
| CVE-2019-12671 | HIGH 7.8 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of th | 0.4% | — |