57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-34694 | MED 4.8 | adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja | 0.2% | — |
| CVE-2026-33006 | MED 4.8 | apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 0.6% | — |
| CVE-2026-32794 | MED 4.8 | apache airflow_providers_databricks Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulat | 0.4% | — |
| CVE-2026-28714 | MED 4.8 | acronis cyber_protect Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-26145 | MED 4.8 | microsoft azure_synapse Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-2485 | MED 4.8 | ibm infosphere_information_server IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading | 0.2% | — |
| CVE-2026-22751 | MED 4.8 | vmware spring_security Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4. | 0.1% | — |
| CVE-2026-20132 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected | 0.2% | — |
| CVE-2026-20111 | MED 4.8 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability | 0.2% | — |
| CVE-2026-20090 | MED 4.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validat | 0.2% | — |
| CVE-2026-20089 | MED 4.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validat | 0.2% | — |
| CVE-2026-20088 | MED 4.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validat | 0.2% | — |
| CVE-2026-20087 | MED 4.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validat | 0.2% | — |
| CVE-2026-20076 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to i | 0.3% | — |
| CVE-2026-20075 | MED 4.8 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the i | 0.2% | — |
| CVE-2026-20047 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the i | 0.3% | — |
| CVE-2026-14154 | MED 4.8 | google chrome Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-0266 | MED 4.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series fi | 0.1% | — |
| CVE-2026-0256 | MED 4.8 | paloaltonetworks pan-os A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Se | 0.2% | — |
| CVE-2025-68161 | MED 4.8 | apache log4j The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-att | 0.8% | — |
| CVE-2025-59501 | MED 4.8 | microsoft configuration_manager_2403 Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | 3.0% | — |
| CVE-2025-55248 | MED 4.8 | microsoft .net Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-54101 | MED 4.8 | microsoft windows_10_1507 Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | 2.5% | — |
| CVE-2025-53608 | MED 4.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 0.3% | — |
| CVE-2025-29891 | MED 4.8 | apache camel Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 | 75.1% | — |