57.872 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.872 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-81378 | HIGH 8.2 | microsoft visual_studio_code Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-81357 | HIGH 8.2 | microsoft visual_studio_code Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-81356 | HIGH 8.2 | microsoft visual_studio_code Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-81354 | HIGH 8.2 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-76413 | HIGH 8.2 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper | — | — |
| CVE-2026-76191 | HIGH 8.2 | adobe animate Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary | 0.3% | — |
| CVE-2026-69906 | HIGH 8.2 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69874 | HIGH 8.2 | microsoft windows_10_1809 Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69846 | HIGH 8.2 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69820 | HIGH 8.2 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69306 | HIGH 8.2 | microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-64448 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one byte large | 0.5% | — |
| CVE-2026-64435 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ_ONCE(), while kaudit | 0.3% | — |
| CVE-2026-64389 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmss | 0.5% | — |
| CVE-2026-64380 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remainin | 0.4% | — |
| CVE-2026-64287 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register save and restore use u | 0.2% | — |
| CVE-2026-64286 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest co | 0.2% | — |
| CVE-2026-60005 | HIGH 8.2 | f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause | 0.7% | — |
| CVE-2026-5944 | HIGH 8.2 | cisco intersight_device_connector An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment witho | 0.5% | — |
| CVE-2026-59324 | HIGH 8.2 | vmware spring_integration When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propaga | 0.2% | — |
| CVE-2026-58525 | HIGH 8.2 | microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-58188 | HIGH 8.2 | apache traffic_server Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to vers | 0.4% | — |
| CVE-2026-58184 | HIGH 8.2 | apache traffic_server The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users | 0.3% | — |
| CVE-2026-58159 | HIGH 8.2 | apache traffic_server Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade | 0.3% | — |
| CVE-2026-57239 | HIGH 8.2 | foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. | 0.2% | — |