IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-69784 HIGH 8.8 microsoft windows_10_21h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69740 HIGH 8.8 microsoft windows_11_23h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69725 HIGH 7.8 microsoft windows_10_21h2 Double free in Windows Hello allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69603 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-65662 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. 0.3% —
CVE-2026-62798 MED 5.5 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. 0.3% —
CVE-2026-62796 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3% —
CVE-2026-62793 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3% —
CVE-2026-62786 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.3% —
CVE-2026-49326 MED 6.5 apache hbase Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for i 0.3% —
CVE-2026-46303 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checkin 0.3% —
CVE-2026-42357 MED 6.5 apache dolphinscheduler Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to v 0.3% —
CVE-2026-40975 MED 4.8 vmware spring_boot Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (f 0.3% —
CVE-2026-33519 CRIT 9.8 esri portal_for_arcgis An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. 0.3% —
CVE-2026-11076 HIGH 8.8 google chrome Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.3% —
CVE-2025-64658 HIGH 7.5 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-38728 CRIT 9.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it is possible to get a slab out of bounds during mount to ksmbd due to missing check in parse_server_interfaces() (see 0.3% —
CVE-2024-49514 HIGH 7.8 adobe photoshop Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction 0.3% —
CVE-2024-42083 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, 0.3% —
CVE-2024-27024 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_conn_connect_if_down If connection isn't established yet, get_mr() will fail, trigger connection after get_mr(). 0.3% —
CVE-2024-26773 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allo 0.3% —
CVE-2024-20369 MED 4.7 cisco network_services_orchestrator A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation 0.3% —
CVE-2023-6679 MED 5.5 fedoraproject fedora A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service. 0.3% —
CVE-2023-4208 HIGH 7.8 debian debian_linux A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. When u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of 0.3% —
CVE-2023-23454 MED 5.5 debian debian_linux cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class 0.3% —