IT
58.458 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.458 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-62738 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-62730 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-62709 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-62703 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-61933 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-61347 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-18639 HIGH 7.3 When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually veri 0.4% —
CVE-2026-44613 MED 6.1 apache zeppelin Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a                    0.4% —
CVE-2026-64374 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT RT migration is done aggressively. When a CPU schedules out a high priority RT task for a lower priority task, it will look to se 0.4% —
CVE-2026-13925 HIGH 7.5 google chrome Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium 0.4% —
CVE-2026-53268 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This h 0.4% —
CVE-2026-11118 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) 0.4% —
CVE-2026-26124 MED 6.7 microsoft aci_confidential_containers '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59281 HIGH 7.8 microsoft xbox_gaming_services Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-59221 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4% —
CVE-2025-20336 MED 5.3 cisco desk_phone_9841_firmware A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnera 0.4% —
CVE-2024-26243 HIGH 7.0 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.4% —
CVE-2024-26236 HIGH 7.0 microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability 0.4% —
CVE-2023-38138 HIGH 7.5 f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End o 0.4% —
CVE-2023-20180 MED 4.3 cisco webex_meetings A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web 0.4% —
CVE-2023-27378 HIGH 7.5 f5 big-ip_access_policy_manager Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached 0.4% —
CVE-2023-1989 HIGH 7.0 debian debian_linux A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices. 0.4% —
CVE-2023-26336 HIGH 7.8 adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.4% —
CVE-2023-25899 HIGH 7.8 adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.4% —
CVE-2023-25896 HIGH 7.8 adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malic 0.4% —