IT
56.743 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.743 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-62696 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 3.4%
CVE-2026-62695 HIGH 7.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62693 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62692 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62690 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62688 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62440 CRIT 9.1 apache cloudstack Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. 0.2%
CVE-2026-62418 HIGH 8.1 apache syncope Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. 0.5%
CVE-2026-62393 MED 4.3 apache kylin Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 th 0.5%
CVE-2026-62392 CRIT 9.8 apache kylin Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recom 2.5%
CVE-2026-62391 HIGH 8.1 apache kyuubi The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache 0.5%
CVE-2026-62390 CRIT 9.8 apache kylin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Us 0.7%
CVE-2026-62354 MED 4.3 apache nifi Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to in 0.3%
CVE-2026-62183 CRIT 9.8 apache syncope Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration 0.7%
CVE-2026-61939 HIGH 7.0 microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61938 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61937 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61936 MED 5.5 microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-61934 HIGH 7.8 microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61933 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61932 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61930 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.1%
CVE-2026-61929 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1.7%
CVE-2026-61928 MED 5.5 microsoft windows_10_1607 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-61927 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%