IT
56.784 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.784 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-21524 HIGH 7.4 microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-21523 HIGH 8.0 microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. 0.8%
CVE-2026-21522 MED 6.7 microsoft confcom Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21521 HIGH 7.4 microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-21520 HIGH 7.5 microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector 1.4%
CVE-2026-21518 HIGH 8.8 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 1.4%
CVE-2026-21517 MED 4.7 microsoft windows_app Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21516 HIGH 8.8 microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-21515 CRIT 9.9 microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-21512 MED 6.5 microsoft azure_devops_server Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. 1.0%
CVE-2026-21511 HIGH 7.5 microsoft 365_apps Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 3.6%
CVE-2026-21508 HIGH 7.0 microsoft windows_10_1607 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21362 HIGH 7.8 adobe illustrator Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open 0.1%
CVE-2026-21358 MED 5.5 adobe indesign InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to servi 0.2%
CVE-2026-21357 HIGH 7.8 adobe indesign InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi 0.2%
CVE-2026-21351 HIGH 7.8 adobe after_effects After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious 0.2%
CVE-2026-21350 MED 5.5 adobe after_effects After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitati 0.1%
CVE-2026-21347 HIGH 7.8 adobe bridge Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m 0.2%
CVE-2026-21346 HIGH 7.8 adobe bridge Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a 0.1%
CVE-2026-21345 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut 0.2%
CVE-2026-21344 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut 0.2%
CVE-2026-21343 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut 0.2%
CVE-2026-21342 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op 0.2%
CVE-2026-21341 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op 0.1%
CVE-2026-21333 HIGH 8.6 adobe illustrator Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim 0.2%