IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-9962 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-62761 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-45843 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith 0.4%
CVE-2026-32794 MED 4.8 apache airflow_providers_databricks Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulat 0.4%
CVE-2026-21517 MED 4.7 microsoft windows_app Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-11074 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) 0.4%
CVE-2026-11068 HIGH 8.8 google chrome Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4%
CVE-2026-11054 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4%
CVE-2025-59277 HIGH 7.8 microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59238 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59226 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59225 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59224 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59223 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-52448 HIGH 8.1 tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: 0.4%
CVE-2025-14917 MED 6.7 ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. 0.4%
CVE-2025-13214 HIGH 7.6 ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0.4%
CVE-2024-52902 HIGH 8.8 ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system. 0.4%
CVE-2024-44988 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array). 0.4%
CVE-2024-35789 HIGH 8.0 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's 0.4%
CVE-2024-20270 MED 4.8 cisco broadworks_application_delivery_platform A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a 0.4%
CVE-2024-20251 MED 4.8 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulner 0.4%
CVE-2023-47059 HIGH 7.8 adobe premiere_pro Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu 0.4%
CVE-2023-47058 HIGH 7.8 adobe premiere_pro Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu 0.4%
CVE-2023-33203 MED 6.4 linux linux_kernel The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. 0.4%