58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8467 | HIGH 7.0 | microsoft windows_10 Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it han | 1.0% | — |
| CVE-2013-4689 | MED 5.1 | juniper junos J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forge | 1.0% | — |
| CVE-2026-8476 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, | 1.0% | — |
| CVE-2026-78509 | CRIT 9.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-78445 | CRIT 9.8 | microsoft windows_server_2012 Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-77493 | CRIT 9.8 | microsoft windows_10_1607 Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-73010 | CRIT 9.8 | microsoft windows_10_1809 Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-73009 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-72983 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-72982 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-72979 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-70296 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69910 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69829 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69824 | CRIT 9.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69819 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69769 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69768 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69730 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69715 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69595 | CRIT 9.8 | microsoft windows_server_2012 Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69590 | CRIT 9.8 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 1.0% | — |
| CVE-2026-69586 | CRIT 9.8 | microsoft windows_10_1607 Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69579 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69525 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.0% | — |