58.273 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.273 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-64903 | HIGH 7.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64898 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63532 | HIGH 7.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63526 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-53180 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle_remote_up() tmigr_handle_remote_cpu() skips timer_expire_remote() when cpu == smp_processor_id(), assuming the local softirq path already handl | 0.3% | — |
| CVE-2026-4679 | HIGH 8.8 | google chrome Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-43253 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommu/amd: move wait_on_sem() out of spinlock With iommu.strict=1, the existing completion wait path can cause soft lockups under stressed environment, as wait_on_sem() busy-waits under the | 0.3% | — |
| CVE-2026-3062 | CRIT 9.8 | google chrome Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-23139 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when GC has been performed Currently last_gc is being updated everytime a new connection is tracked, that means that it is updated even if a GC w | 0.3% | — |
| CVE-2026-20325 | CRIT 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl | 0.3% | — |
| CVE-2026-20248 | MED 6.8 | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response ha | 0.3% | — |
| CVE-2025-37802 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. This m | 0.3% | — |
| CVE-2025-27194 | HIGH 7.8 | adobe media_encoder Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.3% | — |
| CVE-2024-52903 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query. | 0.3% | — |
| CVE-2024-47450 | HIGH 7.8 | adobe illustrator Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open | 0.3% | — |
| CVE-2024-45327 | HIGH 7.5 | fortinet fortisoar An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and | 0.3% | — |
| CVE-2024-45143 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m | 0.3% | — |
| CVE-2024-45139 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m | 0.3% | — |
| CVE-2024-30289 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 0.3% | — |
| CVE-2024-30288 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic | 0.3% | — |
| CVE-2024-20781 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.3% | — |
| CVE-2023-34142 | CRIT 9.0 | hitachi device_manager Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Interception.This issue affects Hitachi Device Manager: before 8.8.5- | 0.3% | — |
| CVE-2023-2019 | MED 4.4 | linux linux_kernel A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system. | 0.3% | — |
| CVE-2022-43750 | MED 6.7 | debian debian_linux drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory. | 0.3% | — |
| CVE-2022-31696 | HIGH 8.8 | vmware cloud_foundation VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | 0.3% | — |