IT
58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-31467 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: erofs: add GFP_NOIO in the bio completion if needed The bio completion path in the process context (e.g. dm-verity) will directly call into decompression rather than trigger another workqueu 0.5% —
CVE-2026-27931 MED 5.5 microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2026-27930 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.5% —
CVE-2026-26133 HIGH 7.1 microsoft 365_copilot AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.5% —
CVE-2025-21766 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear. 0.5% —
CVE-2024-53953 HIGH 7.8 adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.5% —
CVE-2024-53169 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: fix kernel crash while shutting down controller The nvme keep-alive operation, which executes at a periodic interval, could potentially sneak in while shutting down a fabric co 0.5% —
CVE-2024-52997 HIGH 7.8 adobe photoshop Photoshop Desktop versions 26.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.5% —
CVE-2024-49875 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: map the EBADMSG to nfserr_io to avoid warning Ext4 will throw -EBADMSG through ext4_readdir when a checksum error occurs, resulting in the following WARNING. Fix it by mapping EBADMSG 0.5% —
CVE-2024-21445 HIGH 7.0 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.5% —
CVE-2023-4417 MED 6.5 devolutions remote_desktop_manager Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with share 0.5% —
CVE-2022-28875 MED 4.3 f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker. 0.5% —
CVE-2022-22244 MED 5.3 juniper junos An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss 0.5% —
CVE-2022-20967 MED 4.8 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnera 0.5% —
CVE-2011-2183 MED 4.0 linux linux_kernel Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other 0.5% —
CVE-2026-69827 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-69782 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-66802 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-62820 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-62778 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-50460 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-50365 HIGH 8.0 microsoft windows_10_1607 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. 0.5% —
CVE-2026-42900 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-39455 HIGH 7.5 f5 big-ip_access_policy_manager When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End o 0.5% —
CVE-2026-33827 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.5% —