58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69496 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69493 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69491 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69463 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-69408 | CRIT 9.8 | microsoft windows_10_1607 Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-67643 | CRIT 9.8 | microsoft sql_server_2022 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-67631 | CRIT 9.8 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-66302 | CRIT 9.8 | microsoft skype_for_business_server External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-65816 | CRIT 10.0 | microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-65791 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-62893 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-62878 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-62815 | CRIT 9.8 | microsoft windows_11_23h2 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-56190 | CRIT 9.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-56165 | CRIT 9.8 | microsoft account Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-56159 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-55010 | CRIT 9.8 | microsoft minecraft_bedrock_dedicated_server Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50518 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50447 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-49172 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-48397 | HIGH 8.6 | adobe lightroom Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this is | 1.0% | — |
| CVE-2026-47643 | CRIT 9.8 | microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-47291 | CRIT 9.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-45657 | CRIT 9.8 | microsoft windows_11_23h2 Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-44815 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 1.0% | — |