IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50666 HIGH 8.8 microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-50663 HIGH 8.8 microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2026-50622 HIGH 8.8 apache atlas Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue a 0.3%
CVE-2026-50489 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50477 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50474 HIGH 8.8 microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-50444 HIGH 8.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50438 HIGH 8.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-50413 HIGH 8.8 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50398 HIGH 8.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-50385 HIGH 8.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50382 HIGH 8.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. 0.3%
CVE-2026-50370 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. 0.5%
CVE-2026-50369 HIGH 8.8 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-50360 HIGH 8.8 microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50342 HIGH 8.8 microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50223 HIGH 8.8 apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi 0.7%
CVE-2026-50112 HIGH 8.8 apache cloudstack SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can 0.4%
CVE-2026-49795 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49298 HIGH 8.8 apache airflow A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes re 0.5%
CVE-2026-49179 HIGH 8.8 microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-49178 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-49163 HIGH 8.8 microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-49157 HIGH 8.8 apache activemq Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia oper 0.4%
CVE-2026-48564 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. 0.9%