IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-50673 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50672 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50670 HIGH 8.8 microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50669 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50668 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. 0.4%
CVE-2026-50667 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50666 HIGH 8.8 microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-50665 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-50663 HIGH 8.8 microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2026-50661 MED 6.1 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2026-50659 MED 6.5 microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-50658 HIGH 7.0 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50657 MED 4.7 microsoft defender_for_endpoint Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50656 HIGH 7.8 microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". 11.4%
CVE-2026-50655 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-50653 HIGH 7.5 microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50652 HIGH 7.5 microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. 1.7%
CVE-2026-50651 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50650 HIGH 7.8 microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-50649 HIGH 7.8 microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. 0.9%
CVE-2026-50648 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50647 HIGH 7.5 microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50646 HIGH 7.8 microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. 1.0%
CVE-2026-50645 HIGH 7.5 apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 0.5%
CVE-2026-50634 MED 6.5 apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h 0.3%