58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-65796 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-65789 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-65679 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62889 | HIGH 8.1 | microsoft windows_10_1607 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62819 | HIGH 8.1 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.7% | — |
| CVE-2026-62792 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62781 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50686 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-45635 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-45599 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-45584 | HIGH 8.1 | microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42987 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42981 | HIGH 8.1 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42974 | HIGH 8.1 | microsoft windows_11_23h2 Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42895 | MED 6.5 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-42893 | HIGH 7.4 | microsoft outlook Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-40415 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-31533 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto r | 0.7% | — |
| CVE-2026-27928 | HIGH 8.7 | microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. | 0.7% | — |
| CVE-2025-48795 | MED 5.6 | apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic | 0.7% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26797 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26794 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26790 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-21096 | MED 5.5 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in | 0.7% | — |