IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-42971 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-42970 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42969 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42968 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42915 MED 5.5 microsoft windows_10_21h2 Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. 0.4%
CVE-2026-42906 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-41612 MED 5.5 microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-41087 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-40951 MED 5.5 absolute secure_access CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. 0.1%
CVE-2026-40422 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-3777 MED 5.5 foxit pdf_editor The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object m 0.1%
CVE-2026-3776 MED 5.5 foxit pdf_editor The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior nu 0.1%
CVE-2026-35440 MED 5.5 microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-35419 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-34705 MED 5.5 adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issu 0.2%
CVE-2026-34704 MED 5.5 adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser 0.1%
CVE-2026-34703 MED 5.5 adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser 0.2%
CVE-2026-34663 MED 5.5 adobe illustrator Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue req 0.2%
CVE-2026-34662 MED 5.5 adobe illustrator Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service 0.2%
CVE-2026-34657 MED 5.5 adobe c2pa CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could lev 0.2%
CVE-2026-34349 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-34346 MED 5.5 microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-34339 MED 5.5 microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. 0.3%
CVE-2026-34328 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-33842 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%