IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-69445 HIGH 7.8 microsoft windows_10_1607 Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-69289 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-68896 HIGH 7.8 microsoft windows_11_23h2 Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-62812 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-62807 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-62803 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-62776 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-62761 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-61358 HIGH 7.8 microsoft windows_10_1809 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-59083 CRIT 9.1 apache tomcat Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 0.4% —
CVE-2026-58636 HIGH 7.8 microsoft pc_manager Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-57085 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0.4% —
CVE-2026-50511 HIGH 7.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-50469 HIGH 7.8 microsoft windows_10_1809 Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-50454 HIGH 7.8 microsoft windows_11_24h2 Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-50438 HIGH 8.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-45586 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-42989 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-42834 HIGH 7.8 microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.4% —
CVE-2026-32193 HIGH 8.8 microsoft azure_kubernetes_service Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. 0.4% —
CVE-2026-26128 HIGH 7.8 microsoft windows_10_1607 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-25176 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-0310 ND A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-S 0.4% —
CVE-2025-71116 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against corrupted osdmaps If the osdmap is (maliciously) corrupted such that the encoded length of ceph_pg_pool envelope is less than what is expec 0.4% —
CVE-2025-58071 HIGH 7.5 f5 big-ip_access_policy_manager When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —