56.932 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.932 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62793 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-62786 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-62775 | MED 5.5 | microsoft windows_11_26h1 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-62746 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62743 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62740 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62738 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62730 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62709 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-62703 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-61936 | MED 5.5 | microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-61933 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-61928 | MED 5.5 | microsoft windows_10_1607 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | 0.2% | — |
| CVE-2026-61360 | MED 5.5 | microsoft windows_10_1607 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-61347 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-6053 | MED 5.5 | ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables. | 0.1% | — |
| CVE-2026-6051 | MED 5.5 | ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap. | 0.2% | — |
| CVE-2026-60093 | MED 5.5 | apache camel Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component can downloa | 0.2% | — |
| CVE-2026-59839 | MED 5.5 | fortinet fortios A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, F | 0.3% | — |
| CVE-2026-59137 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59136 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59135 | MED 5.5 | microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-59128 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-58614 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-58547 | MED 5.5 | microsoft windows_10_1809 Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. | 0.4% | — |