IT
56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.721 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-27921 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2026-27920 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27919 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27918 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27917 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27916 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27915 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27914 HIGH 7.8 microsoft windows_10_1607 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. 2.6%
CVE-2026-27913 HIGH 7.7 microsoft windows_server_2012 Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-27912 HIGH 8.0 microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. 0.4%
CVE-2026-27911 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27910 HIGH 7.8 microsoft windows_10_1607 Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27909 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2026-27908 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2026-27907 HIGH 7.8 microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27906 MED 4.4 microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-27784 HIGH 7.8 f5 nginx_open_source The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only 1.0%
CVE-2026-27654 HIGH 8.2 f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modificat 21.0%
CVE-2026-27651 HIGH 7.5 f5 nginx_open_source When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server p 0.9%
CVE-2026-2749 CRIT 9.9 centreon open_tickets Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7. 0.5%
CVE-2026-27446 CRIT 9.8 apache artemis Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an att 10.0%
CVE-2026-27316 LOW 2.7 fortinet fortisandbox A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side in 0.3%
CVE-2026-27315 MED 5.5 apache cassandra Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access. Users are recommended to upgrade to version 4.0.20, w 0.2%
CVE-2026-27314 HIGH 8.8 apache cassandra Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that 0.3%
CVE-2026-27313 HIGH 7.8 adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o 0.2%