56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-62390 | CRIT 9.8 | apache kylin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Us | 0.4% | — |
| CVE-2026-62354 | MED 4.3 | apache nifi Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to in | 0.3% | — |
| CVE-2026-62183 | CRIT 9.8 | apache syncope Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration | 0.4% | — |
| CVE-2026-61939 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61938 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61937 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61936 | MED 5.5 | microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-61934 | HIGH 7.8 | microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61933 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-61932 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61930 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2026-61929 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 1.5% | — |
| CVE-2026-61928 | MED 5.5 | microsoft windows_10_1607 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | 0.2% | — |
| CVE-2026-61927 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61926 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61925 | HIGH 7.8 | microsoft windows_10_1607 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61924 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-61923 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-61921 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-61920 | MED 6.6 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-61918 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-61899 | HIGH 7.5 | apache tapestry Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue. | 0.4% | — |
| CVE-2026-61487 | MED 6.5 | apache activemq Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is | 0.5% | — |
| CVE-2026-61486 | CRIT 9.8 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an al | 0.6% | — |
| CVE-2026-61485 | HIGH 7.5 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommend | 0.5% | — |