56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-6052 | MED 6.5 | ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. | 0.2% | — |
| CVE-2026-53360 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things | 0.2% | — |
| CVE-2026-5282 | HIGH 8.1 | google chrome Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-40410 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-32195 | HIGH 7.0 | microsoft windows_11_26h1 Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27917 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26166 | HIGH 7.0 | microsoft windows_11_23h2 Double free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-11680 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-11674 | HIGH 8.8 | google chrome Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-11673 | HIGH 8.8 | google chrome Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-11671 | CRIT 9.6 | google chrome Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-11282 | CRIT 9.6 | google chrome Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-11105 | MED 6.5 | google chrome Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-11096 | MED 6.5 | google chrome Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2025-69274 | HIGH 8.8 | broadcom dx_netops_spectrum Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | 0.2% | — |
| CVE-2025-67704 | MED 6.1 | esri arcgis_server There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim | 0.2% | — |
| CVE-2025-59196 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-54981 | HIGH 7.5 | apache streampark Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: | 0.2% | — |
| CVE-2025-54206 | HIGH 7.8 | adobe indesign InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.2% | — |
| CVE-2025-49570 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 25.12.3, 26.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0.2% | — |
| CVE-2025-49563 | HIGH 7.8 | adobe illustrator Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.2% | — |
| CVE-2025-49528 | HIGH 7.8 | adobe illustrator Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim | 0.2% | — |
| CVE-2025-49527 | HIGH 7.8 | adobe illustrator Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim | 0.2% | — |
| CVE-2025-47134 | HIGH 7.8 | adobe indesign InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.2% | — |
| CVE-2025-47106 | MED 5.5 | adobe indesign InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issu | 0.2% | — |