57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-4295 | MED 6.9 | vmware fusion Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows | 0.3% | — |
| CVE-2010-2525 | HIGH 7.8 | linux linux_kernel A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system. | 0.3% | — |
| CVE-2026-64442 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_ | 0.3% | — |
| CVE-2026-6298 | MED 4.3 | google chrome Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-5867 | MED 4.3 | google chrome Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-45638 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45637 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45605 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45600 | HIGH 7.8 | microsoft windows_11_24h2 Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45593 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45592 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42983 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42910 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41081 | MED 6.5 | apache storm Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (th | 0.3% | — |
| CVE-2026-32156 | HIGH 7.4 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-27924 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26153 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-22627 | HIGH 8.8 | fortinet fortiswitchaxfixed A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the dev | 0.3% | — |
| CVE-2026-20014 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the avail | 0.3% | — |
| CVE-2026-10927 | HIGH 8.3 | google chrome Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10924 | HIGH 8.3 | google chrome Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10921 | HIGH 8.3 | google chrome Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10919 | HIGH 8.3 | google chrome Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10918 | HIGH 8.3 | google chrome Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10909 | HIGH 8.3 | google chrome Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |