IT
58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.285 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-58545 MED 5.5 microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-50312 MED 4.7 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-49167 MED 4.7 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-48569 HIGH 7.1 microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-45169 HIGH 8.6 paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an 0.4% —
CVE-2026-41017 MED 5.9 apache airflow Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards pl 0.4% —
CVE-2026-3542 HIGH 8.8 google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0.4% —
CVE-2026-13445 HIGH 8.1 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor 0.4% —
CVE-2025-58738 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58736 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58734 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58733 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58731 HIGH 7.0 microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-58730 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-54288 MED 6.8 canonical lxd Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device informati 0.4% —
CVE-2025-37952 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks o 0.4% —
CVE-2025-0526 MED 5.4 octopus octopus_server In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. 0.4% —
CVE-2024-26194 HIGH 7.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.4% —
CVE-2023-5197 HIGH 7.8 debian debian_linux A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free. We recom 0.4% —
CVE-2023-35378 HIGH 7.0 microsoft windows_10_1809 Windows Projected File System Elevation of Privilege Vulnerability 0.4% —
CVE-2022-45458 HIGH 7.5 acronis agent Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984. 0.4% —
CVE-2022-45457 HIGH 7.5 acronis agent Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984. 0.4% —
CVE-2022-27050 HIGH 7.8 bitcomet bitcomet BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level. 0.4% —
CVE-2022-20696 HIGH 7.5 cisco catalyst_sd-wan_manager A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnera 0.4% —
CVE-2020-3237 MED 6.3 cisco iox A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on the affected device. The vulnerability is 0.4% —