58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-73008 | MED 5.5 | microsoft windows_10_1607 Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69862 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69684 | MED 5.5 | microsoft windows_10_1607 Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69406 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69351 | MED 5.5 | microsoft windows_10_1607 Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69339 | MED 5.5 | microsoft windows_11_24h2 Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69315 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-69294 | MED 5.5 | microsoft windows_10_1809 Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68886 | MED 5.5 | microsoft windows_10_1607 Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68873 | MED 5.5 | microsoft windows_11_23h2 Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68842 | MED 5.5 | microsoft windows_11_24h2 Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-68579 | CRIT 9.6 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of | 0.5% | — |
| CVE-2026-64210 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this t | 0.5% | — |
| CVE-2026-56184 | MED 5.5 | microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-54123 | MED 5.5 | microsoft defender_for_endpoint Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-53184 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path skb->dev is repurposed as dev_scratch (the truesize/state cache set by udp_set_dev_scratch()), through the union | 0.5% | — |
| CVE-2026-53183 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field in the TCP header refers to the MPTCP-level rcv_nxt and it's right edge should not move backward. Such constrai | 0.5% | — |
| CVE-2026-50681 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50483 | MED 5.5 | microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50473 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50456 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50442 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50434 | MED 5.5 | microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50431 | MED 5.5 | microsoft windows_10_1607 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | 0.5% | — |
| CVE-2026-50430 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | 0.5% | — |