58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-5893 | MED 6.8 | google chrome Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-58528 | MED 6.8 | microsoft windows_10_1809 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0.5% | — |
| CVE-2026-58522 | MED 6.8 | microsoft edge_chromium Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-54132 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-53196 | MED 6.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_obj(), whic | 0.3% | — |
| CVE-2026-50668 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-50507 | MED 6.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.4% | — |
| CVE-2026-50492 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50426 | MED 6.8 | microsoft windows_10_1607 Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2026-50299 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-50298 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-49168 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | 0.4% | — |
| CVE-2026-48312 | MED 6.8 | adobe c2pa CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this | 0.3% | — |
| CVE-2026-47838 | MED 6.8 | vmware spring_security SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. A | 0.2% | — |
| CVE-2026-47837 | MED 6.8 | vmware spring_cloud_config Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 | 0.6% | — |
| CVE-2026-45608 | MED 6.8 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-45585 | MED 6.8 | microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE | 0.5% | — |
| CVE-2026-32223 | MED 6.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0.6% | — |
| CVE-2026-24464 | MED 6.8 | f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versi | 0.9% | — |
| CVE-2026-24288 | MED 6.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-23794 | MED 6.8 | apache syncope Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, f | 0.5% | — |
| CVE-2026-23571 | MED 6.8 | teamviewer digital_employee_experience A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary com | 0.8% | — |
| CVE-2026-22747 | MED 6.8 | vmware spring_security Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an | 0.3% | — |
| CVE-2026-20248 | MED 6.8 | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response ha | 0.3% | — |
| CVE-2026-20050 | MED 6.8 | cisco secure_firewall_threat_defense A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. | 0.4% | — |