58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-63972 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: Skip redundant detach on already-detached port When mana_per_port_queue_reset_work_handler() runs after a previous detach succeeded but attach failed, the port is left in a detach | 0.6% | — |
| CVE-2026-43365 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the superblock doesn't list a log stripe unit, we set the incore log roundoff value to 512. This leads to corrupt logs and unmountable filesys | 0.6% | — |
| CVE-2026-42252 | CRIT 9.1 | apache airflow Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag | 0.6% | — |
| CVE-2026-35565 | MED 5.4 | apache storm Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping valu | 0.6% | — |
| CVE-2025-59240 | MED 5.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-47849 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation | 0.6% | — |
| CVE-2025-47713 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte | 0.6% | — |
| CVE-2024-26009 | HIGH 8.1 | fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, Fo | 0.6% | — |
| CVE-2023-33307 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | 0.6% | — |
| CVE-2021-34760 | MED 4.8 | cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due | 0.6% | — |
| CVE-2021-32600 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information | 0.6% | — |
| CVE-2021-1383 | MED 6.0 | cisco ios_xe Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI comma | 0.6% | — |
| CVE-2019-1857 | MED 6.1 | cisco hx220c_af_m5_firmware A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is d | 0.6% | — |
| CVE-2018-15316 | MED 5.5 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks. | 0.6% | — |
| CVE-2026-23651 | MED 6.7 | microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-23552 | CRIT 9.1 | apache camel Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm | 0.6% | — |
| CVE-2026-10571 | MED 5.7 | ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnecto | 0.6% | — |
| CVE-2025-33075 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24997 | MED 4.4 | microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | 0.6% | — |
| CVE-2025-21235 | HIGH 7.8 | microsoft windows_10_21h2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21234 | HIGH 7.8 | microsoft windows_10_21h2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-49979 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: gso: fix tcp fraglist segmentation after pull from frag_list Detect tcp gso fraglist skbs with corrupted geometry (see below) and pass these to skb_segment instead of skb_segment_list, | 0.6% | — |
| CVE-2024-48988 | HIGH 7.6 | apache streampark SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (Sprin | 0.6% | — |
| CVE-2024-46667 | HIGH 7.5 | fortinet fortisiem A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections. | 0.6% | — |
| CVE-2024-39552 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the RPD process to crash leading to a Denial of Servic | 0.6% | — |