IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-66053 MED 5.9 apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603 0.3%
CVE-2026-65948 HIGH 7.3 apache ranger UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.3%
CVE-2026-65945 MED 6.5 apache ranger Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.3%
CVE-2026-65942 HIGH 7.5 apache ranger TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.4%
CVE-2026-65815 HIGH 8.8 microsoft dynamics_365 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-65814 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65813 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-65811 HIGH 8.8 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-65810 HIGH 7.8 microsoft .net_framework Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-65807 HIGH 8.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-65806 MED 6.5 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-65804 MED 6.1 microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-65802 HIGH 7.4 microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-65799 MED 6.7 microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65798 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65797 MED 6.7 microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65796 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-65795 MED 6.7 microsoft windows_10_1607 Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65794 MED 6.5 microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-65791 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-65790 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65789 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-65788 HIGH 7.0 microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 1.4%
CVE-2026-65787 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65786 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.2%