IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50409 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50394 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50389 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50352 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50339 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50334 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50350 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-50316 MED 5.5 microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-41087 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-34349 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-34328 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-33842 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5% —
CVE-2026-53184 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path skb->dev is repurposed as dev_scratch (the truesize/state cache set by udp_set_dev_scratch()), through the union 0.5% —
CVE-2026-53183 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field in the TCP header refers to the MPTCP-level rcv_nxt and it's right edge should not move backward. Such constrai 0.5% —
CVE-2026-48913 HIGH 7.3 apache http_server Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67. 0.5% —
CVE-2026-33117 CRIT 9.1 microsoft azure_sdk_for_java The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, 0.5% —
CVE-2026-43441 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init 0.5% —
CVE-2026-31477 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leaks and NULL deref in smb2_lock() smb2_lock() has three error handling issues after list_del() detaches smb_lock from lock_list at no_check_cl: 1) If vfs_lock_file() ret 0.5% —
CVE-2025-66388 MED 6.5 apache airflow A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization. Users are recommended to upgr 0.5% —
CVE-2025-13481 HIGH 8.8 ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. 0.5% —
CVE-2025-55231 HIGH 7.5 microsoft windows_server_2012 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2025-32712 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-21338 HIGH 7.8 microsoft office GDI+ Remote Code Execution Vulnerability 0.5% —
CVE-2024-48886 CRIT 9.0 fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver 0.5% —
CVE-2024-49508 HIGH 7.8 adobe indesign InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.5% —