58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-3247 | HIGH 7.2 | linux linux_kernel The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors. | 0.4% | — |
| CVE-2006-0561 | HIGH 7.2 | cisco secure_access_control_server Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptogra | 0.4% | — |
| CVE-2005-0178 | MED 6.2 | linux linux_kernel Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores. | 0.4% | — |
| CVE-2026-59294 | MED 5.9 | vmware spring_ai ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes | 0.4% | — |
| CVE-2026-65777 | MED 5.3 | microsoft windows_11_23h2 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-66318 | HIGH 8.1 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.4% | — |
| CVE-2026-50452 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-50348 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-50634 | MED 6.5 | apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h | 0.4% | — |
| CVE-2026-10945 | HIGH 8.8 | google chrome Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-10893 | HIGH 8.8 | google chrome Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-40974 | MED 5.0 | vmware spring_boot Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), | 0.4% | — |
| CVE-2026-22733 | HIGH 8.2 | vmware spring_boot Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Sec | 0.4% | — |
| CVE-2026-3537 | HIGH 8.8 | google chrome Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-1642 | MED 5.9 | f5 nginx_gateway_fabric A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control | 0.4% | — |
| CVE-2025-53142 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-38379 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix warning when reconnecting channel When reconnecting a channel in smb2_reconnect_server(), a dummy tcon is passed down to smb2_reconnect() with ->query_interface uninitialize | 0.4% | — |
| CVE-2025-37799 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp vmxnet3 driver's XDP handling is buggy for packet sizes using ring0 (that is, packet sizes between 128 - 3k bytes). We noticed MT | 0.4% | — |
| CVE-2025-20153 | MED 5.8 | cisco secure_email_gateway A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. This vulne | 0.4% | — |
| CVE-2024-45146 | HIGH 7.8 | adobe dimension Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fi | 0.4% | — |
| CVE-2024-39386 | HIGH 7.8 | adobe bridge Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 0.4% | — |
| CVE-2024-30273 | HIGH 7.8 | adobe illustrator Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0.4% | — |
| CVE-2023-6006 | HIGH 7.8 | papercut papercut_mf This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a mi | 0.4% | — |
| CVE-2023-32163 | HIGH 7.8 | wacom driver Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low | 0.4% | — |
| CVE-2023-32055 | MED 6.7 | microsoft windows_10_1507 Active Template Library Elevation of Privilege Vulnerability | 0.4% | — |