IT
56.727 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.727 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-26929 MED 6.5 apache airflow Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not a 0.4%
CVE-2026-26184 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26183 HIGH 7.8 microsoft windows_server_2012 Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26182 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26181 HIGH 7.8 microsoft windows_11_23h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26180 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26179 HIGH 7.8 microsoft windows_11_23h2 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-26178 HIGH 8.8 microsoft windows_10_1607 Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-26177 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26176 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26175 MED 4.6 microsoft windows_10_1607 Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2026-26174 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26173 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26172 HIGH 7.8 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26171 HIGH 7.5 microsoft .net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. 1.8%
CVE-2026-26170 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26169 MED 6.1 microsoft windows_10_1607 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. 2.4%
CVE-2026-26168 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26167 HIGH 8.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26166 HIGH 7.0 microsoft windows_11_23h2 Double free in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26165 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26164 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-26163 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26162 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26161 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3%