IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-62714 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-62713 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-62712 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62711 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62710 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62709 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62708 MED 6.4 microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. 0.3%
CVE-2026-62707 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62705 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62703 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62702 MED 6.8 microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. 0.9%
CVE-2026-62701 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62700 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62699 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. 0.4%
CVE-2026-62698 HIGH 7.8 microsoft windows_10_1607 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62696 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 3.2%
CVE-2026-62695 HIGH 7.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62693 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62692 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62690 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62688 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62418 HIGH 8.1 apache syncope Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. 0.3%
CVE-2026-62393 MED 4.3 apache kylin Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 th 0.3%
CVE-2026-62392 CRIT 9.8 apache kylin Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recom 1.3%
CVE-2026-62391 HIGH 8.1 apache kyuubi The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache 0.5%