58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-5592 | MED 5.9 | fortinet fortios_ips_engine Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, when configured with SSL Deep Inspection po | 0.7% | — |
| CVE-2026-83997 | HIGH 8.1 | microsoft windows_10_21h2 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-78450 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-78449 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-78444 | HIGH 8.1 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-77505 | HIGH 8.1 | microsoft windows_10_1607 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-72987 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-72981 | HIGH 8.1 | microsoft windows_10_1607 Use after free in IP Helper allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-72936 | HIGH 8.1 | microsoft windows_11_23h2 Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-71331 | HIGH 8.1 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-70342 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-69989 | HIGH 8.1 | microsoft windows_10_1607 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69858 | HIGH 8.1 | microsoft windows_server_2022 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69813 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69786 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69732 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69620 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69546 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69530 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69524 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69510 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69438 | HIGH 8.1 | microsoft windows_10_1607 Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69325 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-67636 | CRIT 9.0 | microsoft sql_server_2019 Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-67378 | CRIT 9.0 | microsoft sql_server_2019 Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. | 0.7% | — |