IT
56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.721 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-34401 MED 6.5 microsoft xml_notepad XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. 1.0%
CVE-2026-34356 HIGH 7.5 apache http_server Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the is 0.7%
CVE-2026-34355 HIGH 7.5 apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. 1.2%
CVE-2026-34351 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34350 MED 6.5 microsoft windows_server_2025 Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-34349 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-34348 MED 6.5 microsoft windows_10_1809 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. 0.9%
CVE-2026-34347 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34346 MED 5.5 microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-34345 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34344 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34343 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34342 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34341 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34340 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34339 MED 5.5 microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. 0.3%
CVE-2026-34338 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34337 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34336 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34335 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34334 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34333 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34332 HIGH 8.0 microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-34331 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34330 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%