IT
58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2009-2407 MED 6.9 linux linux_kernel Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involvi 0.6% —
CVE-2026-61397 HIGH 7.5 apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. 0.6% —
CVE-2026-59780 HIGH 7.5 apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigura 0.6% —
CVE-2026-59655 HIGH 7.5 apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. 0.6% —
CVE-2026-58179 HIGH 8.1 apache traffic_server The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to up 0.6% —
CVE-2026-56192 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55142 MED 5.5 microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55124 MED 5.5 microsoft 365_apps Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55050 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55047 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55028 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55027 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-55023 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2026-44821 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2025-59258 MED 6.2 microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. 0.6% —
CVE-2025-27728 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-27490 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-24074 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-24073 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-24062 HIGH 7.8 microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-24060 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2025-24058 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6% —
CVE-2024-38016 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.6% —
CVE-2022-41083 HIGH 7.8 microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability 0.6% —
CVE-2022-37999 HIGH 7.8 microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability 0.6% —