58.202 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.202 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-7349 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-7343 | HIGH 7.5 | google chrome Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-7338 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-73017 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | 0.2% | — |
| CVE-2026-72989 | HIGH 7.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-72954 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-72949 | HIGH 7.5 | microsoft windows_11_23h2 Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-72943 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-72932 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-72928 | HIGH 7.5 | microsoft windows_server_2025 Use after free in Windows DNS allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-71559 | HIGH 7.5 | apache fory Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache F | 0.4% | — |
| CVE-2026-71330 | HIGH 7.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-71257 | HIGH 7.5 | apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f | 0.8% | — |
| CVE-2026-70587 | HIGH 7.5 | microsoft windows_10_1607 Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-70469 | HIGH 7.5 | apache nifi Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances | 0.4% | — |
| CVE-2026-70065 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69890 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69881 | HIGH 7.5 | microsoft windows_10_1809 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69852 | HIGH 7.5 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.6% | — |
| CVE-2026-69804 | HIGH 7.5 | microsoft sharepoint_server Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-69793 | HIGH 7.5 | microsoft windows_10_1607 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-69760 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69744 | HIGH 7.5 | microsoft windows_11_24h2 Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69710 | HIGH 7.5 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69631 | HIGH 7.5 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. | 1.2% | — |