57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-35554 | HIGH 8.7 | apache kafka A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still | 0.4% | — |
| CVE-2026-34617 | HIGH 8.7 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, poten | 0.4% | — |
| CVE-2026-34176 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End | 0.7% | — |
| CVE-2026-32673 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c | 0.2% | — |
| CVE-2026-32643 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached | 0.2% | — |
| CVE-2026-27928 | HIGH 8.7 | microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-27173 | HIGH 8.7 | apache apache-airflow-providers-cncf-kubernetes JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and | 0.2% | — |
| CVE-2026-0240 | HIGH 8.7 | paloaltonetworks trust_protection_foundation An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the envir | 0.2% | — |
| CVE-2025-62211 | HIGH 8.7 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-62210 | HIGH 8.7 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-61958 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit | 0.4% | — |
| CVE-2025-59481 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. A successful exploit ca | 0.4% | — |
| CVE-2025-59271 | HIGH 8.7 | microsoft azure_cache_for_redis Redis Enterprise Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-53868 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are | 0.4% | — |
| CVE-2025-53762 | HIGH 8.7 | microsoft purview Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-49154 | HIGH 8.7 | trendmicro apex_one An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected | 0.1% | — |
| CVE-2025-47732 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 3.5% | — |
| CVE-2025-37936 | HIGH 8.7 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value. When generating the MSR_IA32_PEBS_ENABLE value that will be loaded on VM-Entry to a KVM guest, mask the value with t | 0.2% | — |
| CVE-2025-31644 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A s | 26.5% | — |
| CVE-2025-30389 | HIGH 8.7 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-29807 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-23239 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. No | 0.8% | — |
| CVE-2025-22117 | HIGH 8.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw() Fix using the untrusted value of proto->raw.pkt_len in function ice_vc_fdir_parse_raw() by verifying if it does not excee | 0.2% | — |
| CVE-2025-21177 | HIGH 8.7 | microsoft dynamics_365_sales Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-20163 | HIGH 8.7 | cisco nexus_dashboard A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An atta | 0.4% | — |