58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-23004 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1] Crash happens in list_del | 0.1% | — |
| CVE-2026-23001 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source() Add RCU protection on (struct macvlan_source_entry)->vlan. Whenever macvlan_hash_del_source() is called, we must clear entry->vlan poin | 0.2% | — |
| CVE-2026-22999 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: do not free existing class in qfq_change_class() Fixes qfq_change_class() error case. cl->qdisc and cl should only be freed if a new class and qdisc were allocated, or w | 0.2% | — |
| CVE-2026-22995 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_work A race condition exists between the async partition scan work and device teardown that can lead to a use-after-free of ub->ub_disk: 1. u | 0.1% | — |
| CVE-2026-22988 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only dev_hard_header() caller making assumption about skb->head being unchanged. A recent commit broke thi | 0.1% | — |
| CVE-2026-22980 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hashtbl in particularly. We | 0.1% | — |
| CVE-2026-22927 | HIGH 7.8 | omnissa workspace_one_tunnel Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | 0.2% | — |
| CVE-2026-22561 | HIGH 7.8 | anthropic claude Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after | 0.2% | — |
| CVE-2026-21533 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 4.1% | |
| CVE-2026-21519 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 2.5% | |
| CVE-2026-21514 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | 1.6% | |
| CVE-2026-21509 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | 70.8% | |
| CVE-2026-21362 | HIGH 7.8 | adobe illustrator Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open | 0.1% | — |
| CVE-2026-21357 | HIGH 7.8 | adobe indesign InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi | 0.2% | — |
| CVE-2026-21351 | HIGH 7.8 | adobe after_effects After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious | 0.2% | — |
| CVE-2026-21347 | HIGH 7.8 | adobe bridge Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m | 0.2% | — |
| CVE-2026-21346 | HIGH 7.8 | adobe bridge Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 0.1% | — |
| CVE-2026-21345 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut | 0.2% | — |
| CVE-2026-21344 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut | 0.2% | — |
| CVE-2026-21343 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execut | 0.2% | — |
| CVE-2026-21342 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.2% | — |
| CVE-2026-21341 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.1% | — |
| CVE-2026-21330 | HIGH 7.8 | adobe after_effects After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 0.2% | — |
| CVE-2026-21329 | HIGH 7.8 | adobe after_effects After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious | 0.2% | — |
| CVE-2026-21328 | HIGH 7.8 | adobe after_effects After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal | 0.2% | — |