57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-58152 | MED 5.9 | apache traffic_server Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to ve | 0.3% | — |
| CVE-2026-45482 | HIGH 8.4 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-35417 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-25174 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-14055 | CRIT 9.6 | google chrome Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security | 0.3% | — |
| CVE-2026-14024 | HIGH 8.8 | google chrome Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-13920 | CRIT 9.6 | google chrome Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severi | 0.3% | — |
| CVE-2026-13869 | CRIT 9.6 | google chrome Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-10886 | CRIT 9.6 | google chrome Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2025-58071 | HIGH 7.5 | f5 big-ip_access_policy_manager When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-55240 | HIGH 7.3 | microsoft visual_studio_2017 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-49124 | HIGH 8.4 | apache tomcat Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 thro | 0.3% | — |
| CVE-2024-7977 | HIGH 7.8 | google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2024-55599 | MED 5.3 | fortinet fortios An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versi | 0.3% | — |
| CVE-2024-36921 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: guard against invalid STA ID on removal Guard against invalid station IDs in iwl_mvm_mld_rm_sta_id as that would result in out-of-bounds array accesses. This prevents iss | 0.3% | — |
| CVE-2024-27906 | MED 5.9 | apache airflow Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version | 0.3% | — |
| CVE-2023-26411 | HIGH 7.8 | adobe substance_3d_designer Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability t | 0.3% | — |
| CVE-2023-26409 | HIGH 7.8 | adobe substance_3d_designer Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability t | 0.3% | — |
| CVE-2023-26402 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to e | 0.3% | — |
| CVE-2023-26398 | HIGH 7.8 | adobe substance_3d_designer Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability t | 0.3% | — |
| CVE-2023-26393 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to e | 0.3% | — |
| CVE-2023-26391 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to e | 0.3% | — |
| CVE-2023-26389 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to e | 0.3% | — |
| CVE-2023-26371 | HIGH 7.8 | adobe dimension Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute cod | 0.3% | — |
| CVE-2023-21598 | MED 5.5 | adobe incopy Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of thi | 0.3% | — |