58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70105 | MED 6.5 | microsoft microsoft_365 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-70019 | MED 6.5 | microsoft windows_11_23h2 Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-69839 | MED 6.5 | microsoft windows_10_1607 Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69781 | MED 6.5 | microsoft windows_11_24h2 Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | 0.5% | — |
| CVE-2026-69739 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69734 | MED 6.5 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69719 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69683 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69642 | MED 6.5 | microsoft skype_for_business_server Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-69636 | MED 6.5 | microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-69626 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69624 | MED 6.5 | microsoft windows_10_1607 Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-69550 | MED 6.5 | microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-69497 | MED 6.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69409 | MED 6.5 | microsoft sharepoint_server Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-6938 | MED 6.5 | ibm db2 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. | 0.2% | — |
| CVE-2026-69374 | MED 6.5 | microsoft windows_10_21h2 Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69297 | MED 6.5 | microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69267 | MED 6.5 | microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-68971 | MED 6.5 | apache airflow Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manag | 0.3% | — |
| CVE-2026-68970 | MED 6.5 | apache airflow Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string | 0.2% | — |
| CVE-2026-68969 | MED 6.5 | apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level | 0.4% | — |
| CVE-2026-68898 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-68872 | MED 6.5 | apache apache-airflow-providers-amazon The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo | 0.3% | — |
| CVE-2026-68871 | MED 6.5 | apache apache-airflow-providers-apache-yandex The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in | 0.3% | — |