57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-58535 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-58533 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-57979 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-56646 | MED 6.5 | microsoft edge_chromium Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-56197 | HIGH 8.8 | microsoft windows_admin_center Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-55054 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-55003 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-54126 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50519 | MED 6.5 | microsoft github_copilot_chat Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50504 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50497 | MED 6.5 | microsoft windows_10_1607 Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50445 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50376 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-41104 | CRIT 10.0 | microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-30390 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2025-27736 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. | 0.9% | — |
| CVE-2024-42284 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can oc | 0.9% | — |
| CVE-2024-30326 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 0.9% | — |
| CVE-2023-29344 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-35832 | MED 5.5 | microsoft windows_10 Windows Event Tracing Denial of Service Vulnerability | 0.9% | — |
| CVE-2021-33624 | MED 4.7 | debian debian_linux In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db. | 0.9% | — |
| CVE-2020-0783 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0781. | 0.9% | — |
| CVE-2020-0781 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783. | 0.9% | — |
| CVE-2020-0641 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerabi | 0.9% | — |
| CVE-2018-15451 | MED 5.4 | cisco prime_service_catalog A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to | 0.9% | — |