IT
56.596 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.596 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-49799 MED 6.5 microsoft windows_10_1607 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. 0.8%
CVE-2026-49798 CRIT 9.3 microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 2.3%
CVE-2026-49797 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-49796 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-49795 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-49794 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.3%
CVE-2026-49793 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-49792 HIGH 7.8 microsoft windows_10_1607 Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-49791 HIGH 7.1 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49790 HIGH 7.3 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.3%
CVE-2026-49789 HIGH 7.3 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49788 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-49787 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-49784 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-49783 HIGH 7.8 microsoft windows_10_1607 Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-49745 HIGH 7.8 imaginationtech ddk Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which resu 0.1%
CVE-2026-49744 HIGH 7.8 imaginationtech ddk Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow p 0.1%
CVE-2026-49743 HIGH 7.8 imaginationtech ddk Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driv 0.1%
CVE-2026-49488 MED 6.5 apache openmeetings Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files access 0.5%
CVE-2026-49487 MED 6.5 apache airflow In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user w 0.4%
CVE-2026-49486 HIGH 7.5 apache apache-airflow-providers-ftp The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTP 0.3%
CVE-2026-49434 HIGH 7.5 apache activemq Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports i 0.5%
CVE-2026-49432 HIGH 7.5 apache activemq Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For th 0.6%
CVE-2026-49402 HIGH 8.1 deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed 0.3%
CVE-2026-49365 MED 5.3 apache camel Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing erro 0.5%