56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41087 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-40951 | MED 5.5 | absolute secure_access CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. | 0.1% | — |
| CVE-2026-40422 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-3777 | MED 5.5 | foxit pdf_editor The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object m | 0.1% | — |
| CVE-2026-3776 | MED 5.5 | foxit pdf_editor The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior nu | 0.1% | — |
| CVE-2026-35440 | MED 5.5 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-35419 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-34705 | MED 5.5 | adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issu | 0.2% | — |
| CVE-2026-34704 | MED 5.5 | adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser | 0.1% | — |
| CVE-2026-34703 | MED 5.5 | adobe indesign InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser | 0.2% | — |
| CVE-2026-34663 | MED 5.5 | adobe illustrator Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue req | 0.2% | — |
| CVE-2026-34662 | MED 5.5 | adobe illustrator Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service | 0.2% | — |
| CVE-2026-34657 | MED 5.5 | adobe c2pa CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could lev | 0.2% | — |
| CVE-2026-34349 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-34346 | MED 5.5 | microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-34339 | MED 5.5 | microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. | 0.3% | — |
| CVE-2026-34328 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-33842 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-33802 | MED 5.5 | juniper junos A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, | 0.1% | — |
| CVE-2026-33787 | MED 5.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low privileges to cause a complete Denial of Servi | 0.1% | — |
| CVE-2026-33786 | MED 5.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). | 0.1% | — |
| CVE-2026-33776 | MED 5.5 | juniper junos A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. A local user with low privileges can execute the CLI command 'show mgd' with specific arg | 0.1% | — |
| CVE-2026-33452 | MED 5.5 | absolute secure_access CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. | 0.1% | — |
| CVE-2026-33103 | MED 5.5 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | 0.2% | — |
| CVE-2026-32218 | MED 5.5 | microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0.4% | — |