58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-25167 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-24281 | HIGH 7.4 | apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It | 0.6% | — |
| CVE-2026-23364 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq(). | 0.4% | — |
| CVE-2026-21524 | HIGH 7.4 | microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-21521 | HIGH 7.4 | microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-20853 | HIGH 7.4 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20844 | HIGH 7.4 | microsoft windows_10_1607 Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20222 | HIGH 7.4 | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly | 0.2% | — |
| CVE-2026-20074 | HIGH 7.4 | cisco ios_xr A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due | 0.2% | — |
| CVE-2026-19139 | HIGH 7.4 | google chrome Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) | 0.1% | — |
| CVE-2026-10968 | HIGH 7.4 | google chrome Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-0296 | HIGH 7.4 | paloaltonetworks globalprotect Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The Global | 0.1% | — |
| CVE-2025-59960 | HIGH 7.4 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial o | 0.3% | — |
| CVE-2025-59489 | HIGH 7.4 | unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run | 0.6% | — |
| CVE-2025-59210 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2025-59206 | HIGH 7.4 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-59189 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55693 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2025-55687 | HIGH 7.4 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55335 | HIGH 7.4 | microsoft windows_10_1507 Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55077 | HIGH 7.4 | tylertech erp_pro_9 Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed ha | 0.2% | — |
| CVE-2025-54809 | HIGH 7.4 | f5 f5_access F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2025-54103 | HIGH 7.4 | microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0.6% | — |
| CVE-2025-49741 | HIGH 7.4 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 3.6% | — |