58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.414 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20154 | HIGH 8.6 | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause h | 0.4% | — |
| CVE-2026-87648 | HIGH 8.3 | google chrome Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Med | 0.4% | — |
| CVE-2026-87524 | HIGH 8.3 | google chrome Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High | 0.4% | — |
| CVE-2026-83501 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-78454 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-77492 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-72945 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70290 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70145 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69808 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69618 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69609 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69568 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69527 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69457 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69390 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69369 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69353 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69344 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69343 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69318 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69288 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69286 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59270 | CRIT 9.4 | vmware spring_security Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - | 0.4% | — |
| CVE-2026-78952 | HIGH 8.3 | google chrome Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |