57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-10986 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-10978 | HIGH 8.8 | google chrome Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) | 0.3% | — |
| CVE-2025-6505 | HIGH 8.1 | progress hybrid_data_pipeline Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client imper | 0.3% | — |
| CVE-2025-61819 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0.3% | — |
| CVE-2025-53782 | HIGH 8.4 | microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-49726 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-49687 | HIGH 8.8 | microsoft windows_10_1507 Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-43575 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac | 0.3% | — |
| CVE-2025-21195 | MED 6.0 | microsoft azure_service_fabric Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2024-4944 | HIGH 7.8 | watchguard mobile_vpn_with_ssl A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged. | 0.3% | — |
| CVE-2024-20355 | MED 5.0 | cisco adaptive_security_appliance_software A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to success | 0.3% | — |
| CVE-2023-41444 | HIGH 7.8 | binalyze irec An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver. | 0.3% | — |
| CVE-2023-21601 | MED 5.5 | adobe dimension Adobe Dimension version 3.4.6 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires | 0.3% | — |
| CVE-2022-48962 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free | 0.3% | — |
| CVE-2022-48960 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free. | 0.3% | — |
| CVE-2022-48954 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================================================================== BUG: KASAN | 0.3% | — |
| CVE-2022-34683 | MED 5.5 | nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service. | 0.3% | — |
| CVE-2021-44189 | LOW 3.3 | adobe after_effects Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploi | 0.3% | — |
| CVE-2021-38204 | MED 6.8 | debian debian_linux drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. | 0.3% | — |
| CVE-2021-21088 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary c | 0.3% | — |
| CVE-2020-5908 | MED 5.5 | f5 big-ip_access_policy_manager In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files. | 0.3% | — |
| CVE-2020-3971 | MED 5.5 | vmware cloud_foundation VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local acce | 0.3% | — |
| CVE-2020-3115 | HIGH 8.8 | cisco sd-wan_firmware A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. | 0.3% | — |
| CVE-2020-27123 | MED 5.5 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerabil | 0.3% | — |
| CVE-2019-1950 | HIGH 8.4 | cisco ios_xe A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected d | 0.3% | — |