57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-22068 | HIGH 8.2 | apache traffic_server Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. | 0.4% | — |
| CVE-2026-22022 | HIGH 8.2 | apache solr Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that | 0.5% | — |
| CVE-2026-21535 | HIGH 8.2 | microsoft teams Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-21532 | HIGH 8.2 | microsoft azure_functions Azure Function Information Disclosure Vulnerability | 0.9% | — |
| CVE-2026-21227 | HIGH 8.2 | microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-20045 | HIGH 8.2 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection | 4.5% | |
| CVE-2026-14996 | HIGH 8.2 | ibm aspera_faspex IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. | 0.2% | — |
| CVE-2025-71311 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked | 0.3% | — |
| CVE-2025-71072 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: shmem: fix recovery on rename failures maple_tree insertions can fail if we are seriously short on memory; simple_offset_rename() does not recover well if it runs into that. The same goes fo | 0.3% | — |
| CVE-2025-68365 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use KMSAN reports: Multiple uninitialized values detected: - KMSAN: uninit-value in ntfs_read_hdr (3) - KMSAN: uninit-value in bcmp (3) Memory | 0.4% | — |
| CVE-2025-66675 | HIGH 8.2 | apache struts Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1 | 0.6% | — |
| CVE-2025-64677 | HIGH 8.2 | microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-59292 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59291 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-58325 | HIGH 8.2 | fortinet fortios An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI co | 0.3% | — |
| CVE-2025-53787 | HIGH 8.2 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-52454 | HIGH 8.2 | tableau tableau_server Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-52453 | HIGH 8.2 | tableau tableau_server Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19. | 0.3% | — |
| CVE-2025-47977 | HIGH 8.2 | microsoft nuance_digital_engagement_platform Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-38571 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix client side handling of tls alerts A security exploit was discovered in NFS over TLS in tls_alert_recv due to its assumption that there is valid data in the msghdr's iterator's k | 0.3% | — |
| CVE-2025-38491 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/proto | 0.2% | — |
| CVE-2025-37749 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sync_txmung Ensure we have enough data in linear buffer from skb before accessing initial bytes. This prevents potential out-of-bounds access | 0.4% | — |
| CVE-2025-24989 | HIGH 8.2 | microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust | 1.6% | |
| CVE-2025-22249 | HIGH 8.2 | vmware aria_automation VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious craf | 0.3% | — |
| CVE-2025-22225 | HIGH 8.2 | ransomware vmware cloud_foundation VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | 1.0% |