IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-5893 MED 6.8 google chrome Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2026-58528 MED 6.8 microsoft windows_10_1809 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5% —
CVE-2026-58522 MED 6.8 microsoft edge_chromium Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-54132 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-53196 MED 6.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_obj(), whic 0.3% —
CVE-2026-50668 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-50507 MED 6.8 microsoft windows_10_1607 Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4% —
CVE-2026-50492 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-50426 MED 6.8 microsoft windows_10_1607 Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. 0.6% —
CVE-2026-50299 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-50298 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-49168 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. 0.4% —
CVE-2026-48312 MED 6.8 adobe c2pa CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this 0.3% —
CVE-2026-47838 MED 6.8 vmware spring_security SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. A 0.2% —
CVE-2026-47837 MED 6.8 vmware spring_cloud_config Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 0.6% —
CVE-2026-45608 MED 6.8 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-45585 MED 6.8 microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE 0.5% —
CVE-2026-32223 MED 6.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.6% —
CVE-2026-24464 MED 6.8 f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files.  Note: Software versi 0.9% —
CVE-2026-24288 MED 6.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. 0.4% —
CVE-2026-23794 MED 6.8 apache syncope Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, f 0.5% —
CVE-2026-23571 MED 6.8 teamviewer digital_employee_experience A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary com 0.8% —
CVE-2026-22747 MED 6.8 vmware spring_security Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an 0.3% —
CVE-2026-20248 MED 6.8 A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response ha 0.3% —
CVE-2026-20050 MED 6.8 cisco secure_firewall_threat_defense A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. 0.4% —