58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70469 | HIGH 7.5 | apache nifi Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances | 0.4% | — |
| CVE-2026-70065 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69890 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69881 | HIGH 7.5 | microsoft windows_10_1809 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69852 | HIGH 7.5 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.7% | — |
| CVE-2026-69809 | HIGH 7.5 | microsoft windows_11_23h2 Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69804 | HIGH 7.5 | microsoft sharepoint_server Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-69793 | HIGH 7.5 | microsoft windows_10_1607 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-69760 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69744 | HIGH 7.5 | microsoft windows_11_24h2 Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69710 | HIGH 7.5 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69631 | HIGH 7.5 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69607 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69599 | HIGH 7.5 | microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69588 | HIGH 7.5 | microsoft windows_11_23h2 Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69587 | HIGH 7.5 | microsoft windows_11_23h2 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69539 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-69514 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69443 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-69429 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69428 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69397 | HIGH 7.5 | microsoft windows_10_1809 Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69342 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-68981 | HIGH 7.5 | apache nifi Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing | 0.5% | — |
| CVE-2026-68968 | HIGH 7.5 | apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative | 0.4% | — |