58.449 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.449 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20353 | CRIT 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.4% | — |
| CVE-2026-72937 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69794 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69770 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69741 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-69672 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-3921 | HIGH 8.8 | google chrome Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2025-63372 | MED 4.3 | articentgroup zip_rar_extractor_tool Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents. | 0.4% | — |
| CVE-2025-49659 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2024-53141 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefor | 0.4% | — |
| CVE-2023-38217 | MED 5.5 | adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit | 0.4% | — |
| CVE-2023-25874 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25868 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-25864 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0.4% | — |
| CVE-2023-22243 | HIGH 7.8 | adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact | 0.4% | — |
| CVE-2023-22236 | HIGH 7.8 | adobe animate Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.4% | — |
| CVE-2023-22234 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush version 2.6 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0.4% | — |
| CVE-2023-22226 | HIGH 7.8 | adobe bridge Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.4% | — |
| CVE-2023-21536 | MED 4.7 | microsoft windows_10_1809 Event Tracing for Windows Information Disclosure Vulnerability | 0.4% | — |
| CVE-2022-40750 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0.4% | — |
| CVE-2022-20824 | HIGH 8.8 | cisco mds_9506_firmware A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected | 0.4% | — |
| CVE-2021-22118 | HIGH 7.8 | netapp hci In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify fil | 0.4% | — |
| CVE-2019-1601 | HIGH 7.8 | cisco nx-os A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict filesystem permissions on | 0.4% | — |
| CVE-2018-15371 | MED 6.7 | cisco ios_xe A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affe | 0.4% | — |
| CVE-2018-11232 | MED 5.5 | linux linux_kernel The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrectly used as a local variable. | 0.4% | — |