58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69794 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69770 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69741 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69672 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69618 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69353 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68079 | CRIT 9.8 | apache cxf In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization co | 0.4% | — |
| CVE-2026-62871 | HIGH 7.8 | microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-53253 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a short BNEP SDU. bnep_rx_frame() reads the packet type byte immediately and, for control packets, reads the control | 0.4% | — |
| CVE-2026-5278 | HIGH 8.8 | google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-20353 | CRIT 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.4% | — |
| CVE-2024-53141 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefor | 0.4% | — |
| CVE-2023-38217 | MED 5.5 | adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit | 0.4% | — |
| CVE-2023-25874 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25868 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25864 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-22243 | HIGH 7.8 | adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact | 0.4% | — |
| CVE-2023-22236 | HIGH 7.8 | adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.4% | — |
| CVE-2023-22234 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush version 2.6 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0.4% | — |
| CVE-2023-22226 | HIGH 7.8 | adobe bridge Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.4% | — |
| CVE-2023-21536 | MED 4.7 | microsoft windows_10_1809 Event Tracing for Windows Information Disclosure Vulnerability | 0.4% | — |
| CVE-2022-40750 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0.4% | — |
| CVE-2022-20824 | HIGH 8.8 | cisco mds_9506_firmware A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected | 0.4% | — |
| CVE-2021-22118 | HIGH 7.8 | netapp hci In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify fil | 0.4% | — |
| CVE-2019-1601 | HIGH 7.8 | cisco nx-os A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict filesystem permissions on | 0.4% | — |