IT
58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.046 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-42322 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.5%
CVE-2021-38571 HIGH 7.8 foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. 0.5%
CVE-2021-3031 MED 4.3 paloaltonetworks pan-os Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information 0.5%
CVE-2019-17055 LOW 3.3 canonical ubuntu_linux base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21. 0.5%
CVE-2017-18550 MED 5.5 linux linux_kernel An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure. 0.5%
CVE-2018-16597 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem. 0.5%
CVE-2016-7461 HIGH 8.8 vmware fusion The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denia 0.5%
CVE-2011-1776 MED 6.1 linux linux_kernel The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (hea 0.5%
CVE-2004-1234 LOW 2.1 linux linux_kernel load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL. 0.5%
CVE-2026-78513 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-78506 MED 5.5 microsoft 365_apps Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-62801 MED 6.5 microsoft windows_10_1607 Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network. 0.5%
CVE-2026-68782 CRIT 9.9 microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-73240 CRIT 9.8 apache allura Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. 0.5%
CVE-2026-57084 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-57083 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-56195 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-55138 MED 5.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-55057 MED 5.5 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-55046 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-55042 MED 5.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-50408 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-48580 MED 5.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-58297 HIGH 7.1 microsoft edge_chromium Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-58296 HIGH 7.1 microsoft edge_chromium Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0.5%