58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-4005 | HIGH 7.2 | linux linux_kernel The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read. | 0.4% | — |
| CVE-2026-79194 | HIGH 8.1 | google chrome Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-71407 | MED 5.6 | fortinet fortios A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon vi | 0.4% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-53355 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distin | 0.4% | — |
| CVE-2026-47835 | HIGH 8.6 | vmware spring_ai In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store | 0.4% | — |
| CVE-2026-41717 | HIGH 8.1 | vmware spring_data_mongodb Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affecte | 0.4% | — |
| CVE-2026-24282 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-13787 | HIGH 8.1 | google chrome Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2025-26684 | MED 6.7 | microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-11933 | MED 6.5 | wolfssl wolfssl Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions. | 0.4% | — |
| CVE-2024-49535 | MED 6.3 | adobe acrobat Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input conta | 0.4% | — |
| CVE-2023-51560 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 0.4% | — |
| CVE-2023-47074 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu | 0.4% | — |
| CVE-2023-44159 | HIGH 7.5 | acronis cyber_protect Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.4% | — |
| CVE-2023-26337 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2023-25898 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2023-25897 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2023-25895 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2023-25890 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2023-25885 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.4% | — |
| CVE-2022-45051 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The module parameter on the Service.template.cls endpoint does not properly neutralise user input, resulting in the vulnerability. | 0.4% | — |
| CVE-2022-45049 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The url parameter on the novelist.php endpoint does not properly neutralise user input, resulting in the vulnerability. | 0.4% | — |
| CVE-2022-31655 | MED 5.4 | vmware vrealize_log_insight VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts. | 0.4% | — |
| CVE-2022-31654 | MED 5.4 | vmware vrealize_log_insight VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations. | 0.4% | — |