IT
58.532 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.532 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-26176 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26170 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26163 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26162 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26161 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26153 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26134 HIGH 7.8 microsoft 365_copilot Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26132 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2025-69267 MED 6.5 broadcom dx_netops_spectrum Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. 0.3% —
CVE-2025-61819 HIGH 7.8 adobe photoshop Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus 0.3% —
CVE-2025-6505 HIGH 8.1 progress hybrid_data_pipeline Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client imper 0.3% —
CVE-2025-38411 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs request finishes during the pause loop, it will have the ref that belongs to the IN_PROGRESS flag removed at that point - however, if it then goes 0.3% —
CVE-2025-38209 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvm 0.3% —
CVE-2024-57997 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation size KASAN reported a memory allocation issue in wcn->chan_survey due to incorrect size calculation. This commit uses kcalloc to allocate 0.3% —
CVE-2022-48962 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free 0.3% —
CVE-2022-48960 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free. 0.3% —
CVE-2022-48954 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================================================================== BUG: KASAN 0.3% —
CVE-2024-20355 MED 5.0 cisco adaptive_security_appliance_software A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to success 0.3% —
CVE-2021-47160 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link a 0.3% —
CVE-2021-44189 LOW 3.3 adobe after_effects Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploi 0.3% —
CVE-2023-21601 MED 5.5 adobe dimension Adobe Dimension version 3.4.6 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires 0.3% —
CVE-2022-34683 MED 5.5 nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service. 0.3% —
CVE-2022-3606 LOW 3.5 linux linux_kernel A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to 0.3% —
CVE-2021-38204 MED 6.8 debian debian_linux drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. 0.3% —
CVE-2020-27123 MED 5.5 cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerabil 0.3% —