IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-70469 HIGH 7.5 apache nifi Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances 0.4% —
CVE-2026-70065 HIGH 7.5 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69890 HIGH 7.5 microsoft windows_10_1809 Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-69881 HIGH 7.5 microsoft windows_10_1809 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69852 HIGH 7.5 microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine 0.7% —
CVE-2026-69809 HIGH 7.5 microsoft windows_11_23h2 Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69804 HIGH 7.5 microsoft sharepoint_server Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.5% —
CVE-2026-69793 HIGH 7.5 microsoft windows_10_1607 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. 0.8% —
CVE-2026-69760 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. 1.1% —
CVE-2026-69744 HIGH 7.5 microsoft windows_11_24h2 Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network. 1.1% —
CVE-2026-69710 HIGH 7.5 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69631 HIGH 7.5 microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69607 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-69599 HIGH 7.5 microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-69588 HIGH 7.5 microsoft windows_11_23h2 Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69587 HIGH 7.5 microsoft windows_11_23h2 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69539 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0.5% —
CVE-2026-69514 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-69443 HIGH 7.5 microsoft windows_10_1809 Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-69429 HIGH 7.5 microsoft windows_10_1809 Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-69428 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-69397 HIGH 7.5 microsoft windows_10_1809 Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-69342 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-68981 HIGH 7.5 apache nifi Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing 0.5% —
CVE-2026-68968 HIGH 7.5 apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative 0.4% —