58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.285 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-58545 | MED 5.5 | microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-50312 | MED 4.7 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-49167 | MED 4.7 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-48569 | HIGH 7.1 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-45169 | HIGH 8.6 | paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an | 0.4% | — |
| CVE-2026-41017 | MED 5.9 | apache airflow Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards pl | 0.4% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-13445 | HIGH 8.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor | 0.4% | — |
| CVE-2025-58738 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58736 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58734 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58733 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58731 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-58730 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-54288 | MED 6.8 | canonical lxd Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device informati | 0.4% | — |
| CVE-2025-37952 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks o | 0.4% | — |
| CVE-2025-0526 | MED 5.4 | octopus octopus_server In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. | 0.4% | — |
| CVE-2024-26194 | HIGH 7.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.4% | — |
| CVE-2023-5197 | HIGH 7.8 | debian debian_linux A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free. We recom | 0.4% | — |
| CVE-2023-35378 | HIGH 7.0 | microsoft windows_10_1809 Windows Projected File System Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-45458 | HIGH 7.5 | acronis agent Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984. | 0.4% | — |
| CVE-2022-45457 | HIGH 7.5 | acronis agent Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984. | 0.4% | — |
| CVE-2022-27050 | HIGH 7.8 | bitcomet bitcomet BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level. | 0.4% | — |
| CVE-2022-20696 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnera | 0.4% | — |
| CVE-2020-3237 | MED 6.3 | cisco iox A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on the affected device. The vulnerability is | 0.4% | — |