58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69357 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69340 | HIGH 7.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69337 | HIGH 7.1 | microsoft windows_10_1607 Double free in Windows Registry allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69314 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69305 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69296 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69274 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-68893 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-68846 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-68835 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-66322 | HIGH 7.1 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-66305 | HIGH 7.1 | microsoft skype_for_business_server Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-65675 | HIGH 7.1 | microsoft github_copilot_chat No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-64880 | HIGH 7.1 | tenable security_center Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | 0.3% | — |
| CVE-2026-64452 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error path lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding lowpan_nhc_lock. If the descriptor has no uncompress callback, the | 0.2% | — |
| CVE-2026-64436 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp states pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm name: x->ca | 0.1% | — |
| CVE-2026-64422 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP socket state. The sysctl is stored as an `int` but cop | 0.1% | — |
| CVE-2026-64412 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module(). | 0.1% | — |
| CVE-2026-64411 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_table_lock() without NUL- | 0.1% | — |
| CVE-2026-64407 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() During the v3 firmware download the controller sends a v3_data_req with a 32 bit offset and a 16 bit len. nxp_re | 0.1% | — |
| CVE-2026-64403 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately dereferences | 0.3% | — |
| CVE-2026-64379 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in modefromsid When modefromsid is active, parse_dacl() applies the server-provided sub_auth[2] value from the NFS mode SID to cf_mode without | 0.3% | — |
| CVE-2026-64339 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: bound bulk IN response length to the received transfer usbio_bulk_msg() copies bpkt_len = le16_to_cpu(bpkt->len) bytes out of the bulk IN buffer (usbio->rxbuf, allocated wi | 0.2% | — |
| CVE-2026-64323 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the | 0.2% | — |
| CVE-2026-64318 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe array aix_partition() reads the physical volume descriptor into a fixed-size struct pvd and then scans its physical-partition-extent array | 0.2% | — |