58.532 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.532 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-26176 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26170 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26163 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26162 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26161 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26153 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26134 | HIGH 7.8 | microsoft 365_copilot Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26132 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-69267 | MED 6.5 | broadcom dx_netops_spectrum Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | 0.3% | — |
| CVE-2025-61819 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0.3% | — |
| CVE-2025-6505 | HIGH 8.1 | progress hybrid_data_pipeline Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client imper | 0.3% | — |
| CVE-2025-38411 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs request finishes during the pause loop, it will have the ref that belongs to the IN_PROGRESS flag removed at that point - however, if it then goes | 0.3% | — |
| CVE-2025-38209 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvm | 0.3% | — |
| CVE-2024-57997 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation size KASAN reported a memory allocation issue in wcn->chan_survey due to incorrect size calculation. This commit uses kcalloc to allocate | 0.3% | — |
| CVE-2022-48962 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free | 0.3% | — |
| CVE-2022-48960 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free. | 0.3% | — |
| CVE-2022-48954 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================================================================== BUG: KASAN | 0.3% | — |
| CVE-2024-20355 | MED 5.0 | cisco adaptive_security_appliance_software A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to success | 0.3% | — |
| CVE-2021-47160 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link a | 0.3% | — |
| CVE-2021-44189 | LOW 3.3 | adobe after_effects Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploi | 0.3% | — |
| CVE-2023-21601 | MED 5.5 | adobe dimension Adobe Dimension version 3.4.6 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires | 0.3% | — |
| CVE-2022-34683 | MED 5.5 | nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service. | 0.3% | — |
| CVE-2022-3606 | LOW 3.5 | linux linux_kernel A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to | 0.3% | — |
| CVE-2021-38204 | MED 6.8 | debian debian_linux drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. | 0.3% | — |
| CVE-2020-27123 | MED 5.5 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerabil | 0.3% | — |