IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-77502 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-77498 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-69930 MED 5.9 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-68887 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-67643 CRIT 9.8 microsoft sql_server_2022 Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-67376 HIGH 7.5 microsoft sql_server_2017 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-48295 HIGH 7.5 adobe c2pa CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue do 0.8%
CVE-2026-21267 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue req 0.8%
CVE-2025-49688 HIGH 8.8 microsoft windows_server_2012 Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49676 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-49672 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-21324 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21310 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21260 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21258 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21256 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21255 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21249 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21232 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21229 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21228 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2025-21227 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0.8%
CVE-2024-49129 HIGH 7.5 microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 0.8%
CVE-2024-41159 HIGH 7.1 microsoft onenote A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger 0.8%
CVE-2024-31491 HIGH 8.8 fortinet fortisandbox A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests. 0.8%