56.790 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.790 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-24308 | HIGH 7.5 | apache zookeeper Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level | 1.2% | — |
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-24306 | CRIT 9.8 | microsoft azure_front_door Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-24305 | CRIT 9.3 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-24303 | CRIT 9.6 | microsoft partner_center Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-24302 | HIGH 8.6 | microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1.5% | — |
| CVE-2026-24300 | CRIT 9.8 | microsoft azure_front_door Azure Front Door Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2026-24299 | MED 5.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-24297 | MED 6.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-24296 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-24295 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-24294 | HIGH 7.8 | microsoft windows_10_1607 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | 4.7% | — |
| CVE-2026-24293 | HIGH 7.8 | microsoft windows_10_21h2 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-24292 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-24291 | HIGH 7.8 | microsoft windows_10_1607 Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2026-24290 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-24289 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4.5% | — |
| CVE-2026-24288 | MED 6.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. | 0.4% | — |
| CVE-2026-24287 | HIGH 7.8 | microsoft windows_10_1809 External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-24285 | HIGH 7.0 | microsoft 365_copilot Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-24283 | HIGH 8.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-24282 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-24281 | HIGH 7.4 | apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It | 0.6% | — |
| CVE-2026-24266 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |