IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-0391 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-0289 MED 6.5 paloaltonetworks prisma_browser A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. 0.2% —
CVE-2026-0282 MED 6.5 paloaltonetworks pan-os A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by rest 0.3% —
CVE-2026-0249 MED 6.5 paloaltonetworks globalprotect Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system 0.1% —
CVE-2026-0243 MED 6.5 paloaltonetworks prisma_sd-wan A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet. 0.2% —
CVE-2026-0239 MED 6.5 paloaltonetworks chronosphere_collector An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information. 0.2% —
CVE-2026-0203 MED 6.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in 0.3% —
CVE-2025-8881 MED 6.5 google chrome Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2025-69267 MED 6.5 broadcom dx_netops_spectrum Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. 0.3% —
CVE-2025-69233 MED 6.5 apache cloudstack Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by 0.4% —
CVE-2025-68280 MED 6.5 apache spatial_information_system Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache 0.7% —
CVE-2025-66388 MED 6.5 apache airflow A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization. Users are recommended to upgr 0.5% —
CVE-2025-66171 MED 6.5 apache cloudstack The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs us 0.5% —
CVE-2025-66170 MED 6.5 apache cloudstack The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backup 0.5% —
CVE-2025-65995 MED 6.5 apache airflow When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had 0.8% —
CVE-2025-6549 MED 6.5 juniper junos An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper Web Device Manager (J-Web). When Juniper Secure connect (JSC) is enabled on specif 0.2% —
CVE-2025-65082 MED 6.5 apache http_server Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects A 0.8% —
CVE-2025-64670 MED 6.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. 1.0% —
CVE-2025-64402 MED 6.5 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, docum 0.5% —
CVE-2025-62687 MED 6.5 secuavail logstare_collector Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. 0.1% —
CVE-2025-62473 MED 6.5 microsoft windows_10_1607 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.1% —
CVE-2025-62465 MED 6.5 microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-62463 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5% —
CVE-2025-62206 MED 6.5 microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2025-61623 MED 6.5 apache ofbiz Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. 0.8% —