58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-21511 | HIGH 7.5 | microsoft 365_apps Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 3.8% | — |
| CVE-2026-21260 | HIGH 7.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 1.5% | — |
| CVE-2026-21243 | HIGH 7.5 | microsoft windows_server_2019 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2026-21226 | HIGH 7.5 | microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-21218 | HIGH 7.5 | microsoft .net Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2026-20965 | HIGH 7.5 | microsoft windows_admin_center Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-20934 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20929 | HIGH 7.5 | microsoft windows_10_1607 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 2.9% | — |
| CVE-2026-20926 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20921 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2026-20919 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20875 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-20849 | HIGH 7.5 | microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-20848 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20846 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2026-20348 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to imp | 0.5% | — |
| CVE-2026-20343 | HIGH 7.5 | A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker | 0.4% | — |
| CVE-2026-20281 | HIGH 7.5 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS | 0.3% | — |
| CVE-2026-20247 | HIGH 7.5 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sen | 0.3% | — |
| CVE-2026-20244 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20243 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improp | 0.6% | — |
| CVE-2026-20217 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imp | 0.6% | — |
| CVE-2026-20216 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An | 0.6% | — |
| CVE-2026-20215 | HIGH 7.5 | cisco secure_endpoint A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to imprope | 0.6% | — |