IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-54128 HIGH 8.4 microsoft windows_10_1607 Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-54127 HIGH 7.4 microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-54126 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-54125 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-54124 HIGH 7.8 microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-54123 MED 5.5 microsoft defender_for_endpoint Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-54122 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-54121 HIGH 8.8 microsoft windows_10_1607 Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. 1.8%
CVE-2026-54120 CRIT 9.9 microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-54119 HIGH 7.5 microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-54118 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-54117 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-54116 MED 6.5 microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-54115 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-54114 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-54113 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. 1.1%
CVE-2026-54112 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-54111 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-54109 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-54108 MED 6.5 microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.1%
CVE-2026-54107 HIGH 8.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-53917 HIGH 7.5 apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size val 0.7%
CVE-2026-53916 HIGH 7.5 apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer the 0.7%
CVE-2026-53913 CRIT 9.8 apache camel Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.bef 1.1%
CVE-2026-53571 HIGH 7.5 vitejs vite Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through serv 0.6%