58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0380 | HIGH 7.1 | cisco ios The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. | 35.0% | — |
| CVE-1999-0725 | HIGH 7.1 | microsoft internet_information_server When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | 24.9% | — |
| CVE-1999-0723 | HIGH 7.1 | microsoft windows_2000 The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. | 7.3% | — |
| CVE-2026-85360 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83999 | HIGH 7.0 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83940 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-81389 | HIGH 7.0 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-80093 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-78464 | HIGH 7.0 | microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-78457 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77905 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77899 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77894 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77485 | HIGH 7.0 | microsoft sql_server_2017 Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73022 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-73005 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73003 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72963 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72952 | HIGH 7.0 | microsoft windows_10_1809 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-72930 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-72926 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71353 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-71351 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71342 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-71340 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |