IT
57.872 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.872 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-81378 HIGH 8.2 microsoft visual_studio_code Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-81357 HIGH 8.2 microsoft visual_studio_code Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-81356 HIGH 8.2 microsoft visual_studio_code Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-81354 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-76413 HIGH 8.2 A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper
CVE-2026-76191 HIGH 8.2 adobe animate Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary 0.3%
CVE-2026-69906 HIGH 8.2 microsoft windows_10_1607 Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69874 HIGH 8.2 microsoft windows_10_1809 Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69846 HIGH 8.2 microsoft windows_10_1607 Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69820 HIGH 8.2 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69306 HIGH 8.2 microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-64448 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one byte large 0.5%
CVE-2026-64435 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ_ONCE(), while kaudit 0.3%
CVE-2026-64389 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmss 0.5%
CVE-2026-64380 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remainin 0.4%
CVE-2026-64287 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register save and restore use u 0.2%
CVE-2026-64286 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest co 0.2%
CVE-2026-60005 HIGH 8.2 f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause 0.7%
CVE-2026-5944 HIGH 8.2 cisco intersight_device_connector An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment witho 0.5%
CVE-2026-59324 HIGH 8.2 vmware spring_integration When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propaga 0.2%
CVE-2026-58525 HIGH 8.2 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-58188 HIGH 8.2 apache traffic_server Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to vers 0.4%
CVE-2026-58184 HIGH 8.2 apache traffic_server The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users 0.3%
CVE-2026-58159 HIGH 8.2 apache traffic_server Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade 0.3%
CVE-2026-57239 HIGH 8.2 foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. 0.2%