58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-61347 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59270 | CRIT 9.4 | vmware spring_security Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - | 0.4% | — |
| CVE-2026-59137 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59136 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59128 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-58614 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-54997 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50690 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50455 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50437 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50401 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50383 | MED 6.1 | microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50381 | MED 5.5 | microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50341 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50300 | MED 5.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-49801 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-48566 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-45634 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-45604 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-44814 | MED 5.5 | microsoft windows_11_26h1 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-42969 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-42968 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-41954 | MED 4.9 | f5 big-ip_access_policy_manager Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software v | 0.4% | — |
| CVE-2026-40422 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-35419 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |