58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69594 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69576 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69541 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69432 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69407 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69359 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69277 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69269 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68892 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68890 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68888 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68885 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68850 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62810 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-56198 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-22745 | MED 5.3 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * | 0.3% | — |
| CVE-2026-20806 | MED 5.5 | microsoft windows_10_1809 Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2025-47975 | HIGH 7.0 | microsoft windows_10_1507 Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-20129 | MED 4.3 | cisco socialminer A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper s | 0.3% | — |
| CVE-2025-27732 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-20144 | MED 4.0 | cisco ios_xr A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect handling of packets when a specifi | 0.3% | — |
| CVE-2023-23472 | LOW 3.1 | ibm infosphere_information_server IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | 0.3% | — |
| CVE-2024-37070 | MED 4.3 | ibm concert IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | 0.3% | — |
| CVE-2024-8260 | MED 6.1 | openpolicyagent open_policy_agent A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI | 0.3% | — |
| CVE-2024-35887 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer h | 0.3% | — |