IT
58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.290 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-58610 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-58609 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-55948 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-55899 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-54993 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-50675 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-50308 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-49797 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-49796 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2026-47646 CRIT 9.3 microsoft dynamics_365_customer_voice Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. 0.5% —
CVE-2026-58299 HIGH 7.5 microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-10845 HIGH 7.3 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. 0.5% —
CVE-2026-32185 MED 5.5 microsoft teams Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. 0.5% —
CVE-2026-35565 MED 5.4 apache storm Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping valu 0.5% —
CVE-2025-59222 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5% —
CVE-2025-37935 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM If the mtk_poll_rx() function detects the MTK_RESETTING flag, it will jump to release_desc and refill the high word of the SDP on the 0.5% —
CVE-2024-0116 MED 4.9 nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is in use. A successful exploit of this vulnerability may lead to denial of service. 0.5% —
CVE-2024-43864 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix CT entry update leaks of modify header context The cited commit allocates a new modify header to replace the old one when updating CT entry. But if failed to allocate a new on 0.5% —
CVE-2024-39549 HIGH 7.5 juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad 0.5% —
CVE-2024-25705 MED 5.4 esri portal_for_arcgis There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, 0.5% —
CVE-2023-5345 HIGH 7.8 fedoraproject fedora A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead 0.5% —
CVE-2023-21765 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5% —
CVE-2022-2153 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to 0.5% —
CVE-2022-28225 HIGH 7.8 yandex yandex_browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process 0.5% —
CVE-2021-25261 HIGH 7.8 yandex yandex_browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process 0.5% —