IT
57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.057 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2010-4650 MED 4.6 linux linux_kernel Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server. 0.4%
CVE-2026-62746 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62743 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62740 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62738 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62730 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62709 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62703 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61933 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61360 MED 5.5 microsoft windows_10_1607 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61347 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59313 CRIT 9.8 vmware spring_framework Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 S 0.4%
CVE-2026-59137 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59128 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-43296 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky NIX SQ manager sticky mode is known to cause stalls when multiple SQs share an SMQ and transmit concurrently. Additionally, PSE ma 0.4%
CVE-2026-43232 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the 0.4%
CVE-2026-27906 MED 4.4 microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-13925 HIGH 7.5 google chrome Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium 0.4%
CVE-2026-11118 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4%
CVE-2025-63372 MED 4.3 articentgroup zip_rar_extractor_tool Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents. 0.4%
CVE-2025-20336 MED 5.3 cisco desk_phone_9841_firmware A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnera 0.4%
CVE-2024-53954 HIGH 7.8 adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a 0.4%
CVE-2024-26243 HIGH 7.0 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.4%
CVE-2024-26236 HIGH 7.0 microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability 0.4%
CVE-2023-38138 HIGH 7.5 f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End o 0.4%