IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-34693 HIGH 8.0 adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevat 0.3%
CVE-2026-34333 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27919 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27915 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27907 HIGH 7.8 microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26180 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26163 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26162 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26161 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25167 HIGH 7.4 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-15904 HIGH 8.8 google chrome Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2025-66495 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be ac 0.3%
CVE-2025-66494 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacke 0.3%
CVE-2025-66493 HIGH 7.8 foxit pdf_editor A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been free 0.3%
CVE-2025-62631 MED 5.6 fortinet fortios An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN sessio 0.3%
CVE-2025-53768 HIGH 7.8 microsoft windows_10_1507 Use after free in Xbox allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-53150 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-38495 HIGH 8.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, curre 0.3%
CVE-2025-29973 HIGH 7.0 microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2024-40968 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write interface is used to access the configuration space of the peripheral PCIe devices of the mips processor a 0.3%
CVE-2024-39507 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may 0.3%
CVE-2024-39499 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() a 0.3%
CVE-2024-20437 HIGH 8.1 cisco ios_xe A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device. This vulnerability is 0.3%
CVE-2024-0841 MED 6.6 linux linux_kernel A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. 0.3%
CVE-2023-7192 MED 5.5 linux linux_kernel A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow. 0.3%