IT
57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50647 HIGH 7.5 microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50645 HIGH 7.5 apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 0.5%
CVE-2026-50527 HIGH 7.5 microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50525 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2026-50524 HIGH 7.5 microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2026-50506 HIGH 7.5 microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50505 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-50500 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-50496 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2026-50470 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-50463 HIGH 7.5 microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-50424 HIGH 7.5 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50414 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-50411 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50379 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-50368 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50355 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50330 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. 1.3%
CVE-2026-50328 HIGH 7.5 microsoft windows_10_1607 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. 1.2%
CVE-2026-50304 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50222 HIGH 7.5 apache cloudstack Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserData 0.3%
CVE-2026-49975 HIGH 7.5 apache http_server Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. 34.3%
CVE-2026-49788 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-49787 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-49486 HIGH 7.5 apache apache-airflow-providers-ftp The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTP 0.4%