56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.721 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-34401 | MED 6.5 | microsoft xml_notepad XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. | 1.0% | — |
| CVE-2026-34356 | HIGH 7.5 | apache http_server Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the is | 0.7% | — |
| CVE-2026-34355 | HIGH 7.5 | apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | 1.2% | — |
| CVE-2026-34351 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34350 | MED 6.5 | microsoft windows_server_2025 Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-34349 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-34348 | MED 6.5 | microsoft windows_10_1809 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-34347 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34346 | MED 5.5 | microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-34345 | HIGH 7.0 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34344 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34343 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34342 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34341 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34340 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34339 | MED 5.5 | microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. | 0.3% | — |
| CVE-2026-34338 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34337 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34336 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34335 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34334 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34333 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34332 | HIGH 8.0 | microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-34331 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34330 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |