58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-12210 | MED 6.5 | intel graphics_driver Multiple pointer dereferences in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 pote | 0.3% | — |
| CVE-2013-3497 | MED 4.7 | juniper junos_space Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen. | 0.3% | — |
| CVE-2012-4077 | MED 6.8 | cisco nx-os Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651. | 0.3% | — |
| CVE-2010-4248 | MED 4.9 | linux linux_kernel Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and th | 0.3% | — |
| CVE-2006-5871 | MED 4.1 | linux linux_kernel smbfs in Linux kernel 2.6.8 and other versions, and 2.4.x before 2.4.34, when UNIX extensions are enabled, ignores certain mount options, which could cause clients to use server-specified uid, gid and mode settings. | 0.3% | — |
| CVE-1999-0780 | MED 4.6 | freebsd freebsd KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. | 0.3% | — |
| CVE-2026-81379 | HIGH 8.2 | microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-81378 | HIGH 8.2 | microsoft visual_studio_code Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-81356 | HIGH 8.2 | microsoft visual_studio_code Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-76413 | HIGH 8.2 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper | 0.3% | — |
| CVE-2026-70307 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69543 | HIGH 8.5 | microsoft azure_virtual_machines Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | 0.3% | — |
| CVE-2026-65673 | HIGH 7.8 | microsoft entra_connect Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58635 | HIGH 7.8 | microsoft windows_10_1809 Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-5277 | HIGH 7.5 | google chrome Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-50488 | HIGH 7.8 | microsoft windows_11_24h2 Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-46244 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all | 0.3% | — |
| CVE-2026-4461 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-20247 | HIGH 7.5 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sen | 0.3% | — |
| CVE-2025-64156 | HIGH 7.2 | fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticate | 0.3% | — |
| CVE-2025-47182 | MED 5.6 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2025-27177 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.3% | — |
| CVE-2025-27171 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.3% | — |
| CVE-2025-27162 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires | 0.3% | — |
| CVE-2025-24453 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.3% | — |