IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-70587 HIGH 7.5 microsoft windows_10_1607 Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-70579 HIGH 7.5 microsoft windows_10_21h2 Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-69519 HIGH 8.6 microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-69443 HIGH 7.5 microsoft windows_10_1809 Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-62898 HIGH 7.5 microsoft .net Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-50470 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-50463 HIGH 7.5 microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-47633 HIGH 7.5 microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-45639 HIGH 7.5 microsoft remote_desktop_client Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-42908 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-40406 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-33111 HIGH 7.5 microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-26164 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-26129 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2023-44206 CRIT 9.1 acronis cyber_protect Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. 1.0% —
CVE-2023-29255 HIGH 7.5 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991. 1.0% —
CVE-2023-26021 HIGH 7.5 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864. 1.0% —
CVE-2022-34028 HIGH 7.5 f5 njs Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h. 1.0% —
CVE-2022-23909 HIGH 7.8 gimmal sherpa_connector_service There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. 1.0% —
CVE-2021-22982 HIGH 7.2 f5 big-ip_domain_name_system On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) 1.0% —
CVE-2020-17521 MED 5.5 apache atlas Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems 1.0% —
CVE-2019-6686 MED 5.3 f5 big-ip_local_traffic_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K. 1.0% —
CVE-2019-16004 MED 6.5 cisco vision_dynamic_signage_director A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to missing authentication on some of the API calls. An at 1.0% —
CVE-2018-0600 HIGH 7.8 sony playmemories_home Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 1.0% —
CVE-1999-1166 HIGH 7.2 linux linux_kernel Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory. 1.0% —