IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-65796 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-65789 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-65679 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-62889 HIGH 8.1 microsoft windows_10_1607 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-62819 HIGH 8.1 microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine 0.7% —
CVE-2026-62792 HIGH 8.1 microsoft windows_10_1607 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-62781 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-50686 HIGH 8.1 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-45635 HIGH 8.1 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-45599 HIGH 8.1 microsoft windows_10_1607 Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-42987 HIGH 8.1 microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-42981 HIGH 8.1 microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-42974 HIGH 8.1 microsoft windows_11_23h2 Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-42895 MED 6.5 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. 0.7% —
CVE-2026-42893 HIGH 7.4 microsoft outlook Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. 0.7% —
CVE-2026-40415 HIGH 8.1 microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2026-31533 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto r 0.7% —
CVE-2026-27928 HIGH 8.7 microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. 0.7% —
CVE-2025-48795 MED 5.6 apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic 0.7% —
CVE-2022-26938 HIGH 7.0 microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability 0.7% —
CVE-2022-26797 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7% —
CVE-2022-26794 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7% —
CVE-2022-26790 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7% —
CVE-2021-21096 MED 5.5 adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in 0.7% —