57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62883 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62881 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62769 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42919 | MED 6.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached En | 0.3% | — |
| CVE-2026-41097 | MED 6.7 | microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.4% | — |
| CVE-2026-39814 | MED 6.7 | fortinet fortiweb A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or comm | 0.1% | — |
| CVE-2026-39809 | MED 6.7 | fortinet forticlientems A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized | 0.1% | — |
| CVE-2026-33791 | MED 6.7 | juniper junos An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete co | 0.7% | — |
| CVE-2026-32176 | MED 6.7 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32170 | MED 6.7 | microsoft windows_10_1607 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32167 | MED 6.7 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26124 | MED 6.7 | microsoft aci_confidential_containers '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-25691 | MED 6.7 | fortinet fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may | 0.5% | — |
| CVE-2026-23651 | MED 6.7 | microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-21915 | MED 6.7 | juniper virtual_lightweight_collector A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accepts input without caref | 2.2% | — |
| CVE-2026-21530 | MED 6.7 | microsoft windows_10_1607 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21522 | MED 6.7 | microsoft confcom Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20876 | MED 6.7 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-0390 | MED 6.7 | microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-0275 | MED 6.7 | paloaltonetworks prisma_browser A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Bro | 0.2% | — |
| CVE-2025-67862 | MED 6.7 | fortinet fortios An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, F | 0.1% | — |
| CVE-2025-64157 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via s | 1.4% | — |
| CVE-2025-62214 | MED 6.7 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-57716 | MED 6.7 | fortinet forticlient An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClien | 0.2% | — |
| CVE-2025-55309 | MED 6.7 | foxit pdf_editor An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the | 0.1% | — |