56.790 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.790 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-21248 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2026-21247 | HIGH 7.3 | microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-21246 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21245 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21244 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2026-21243 | HIGH 7.5 | microsoft windows_server_2019 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1.3% | — |
| CVE-2026-21242 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21241 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 2.5% | — |
| CVE-2026-21240 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21239 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21238 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2026-21237 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21236 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21235 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2026-21234 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21232 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21231 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2.5% | — |
| CVE-2026-2123 | HIGH 7.8 | microfocus operations_agent A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsul | 0.1% | — |
| CVE-2026-21229 | HIGH 8.0 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-21228 | HIGH 8.1 | microsoft azure_local Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-21227 | HIGH 8.2 | microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-21226 | HIGH 7.5 | microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-21224 | HIGH 7.8 | microsoft azure_connected_machine_agent Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21223 | HIGH 7.1 | microsoft edge_chromium Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-21222 | MED 5.5 | microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0.6% | — |