IT
58.450 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.450 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-70330 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-70304 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69449 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-69373 MED 6.7 microsoft windows_10_1607 Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-69350 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-65799 MED 6.7 microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-65798 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-65797 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-65795 MED 6.7 microsoft windows_10_1607 Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-65680 MED 6.7 microsoft onedrive Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-65129 MED 6.7 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. 0.1% —
CVE-2026-62883 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-62881 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-62769 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42919 MED 6.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached En 0.4% —
CVE-2026-41097 MED 6.7 microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 2.2% —
CVE-2026-39814 MED 6.7 fortinet fortiweb A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or comm 0.2% —
CVE-2026-39809 MED 6.7 fortinet forticlientems A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized 0.2% —
CVE-2026-33791 MED 6.7 juniper junos An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete co 0.7% —
CVE-2026-32176 MED 6.7 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-32170 MED 6.7 microsoft windows_10_1607 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-32167 MED 6.7 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-26124 MED 6.7 microsoft aci_confidential_containers '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-25691 MED 6.7 fortinet fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may 0.5% —
CVE-2026-23651 MED 6.7 microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.6% —