57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-56187 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-54989 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-54129 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50688 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50674 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50491 | HIGH 7.0 | microsoft windows_10_1607 Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50490 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50476 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50406 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50396 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50393 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50390 | HIGH 7.0 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50359 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50358 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50307 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-22992 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned from mon_handle_auth_d | 0.3% | — |
| CVE-2025-37882 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun event handling The TRB pointer of these events points at enqueue at the time of error occurrence on xHCI 1.1+ HCs or it's NULL on older ones. | 0.3% | — |
| CVE-2024-50024 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: Fix an unsafe loop on the list The kernel may crash when deleting a genetlink family if there are still listeners for that family: Oops: Kernel access of bad area, sig: 11 [#1] ... | 0.3% | — |
| CVE-2024-46675 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: Prevent USB core invalid event buffer address access This commit addresses an issue where the USB core could access an invalid event buffer address during runtime suspend, p | 0.3% | — |
| CVE-2024-40987 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix UBSAN warning in kv_dpm.c Adds bounds check for sumo_vid_mapping_entry. | 0.3% | — |
| CVE-2024-35978 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix memory leak in hci_req_sync_complete() In 'hci_req_sync_complete()', always free the previous sync request state before assigning reference to a new one. | 0.3% | — |
| CVE-2024-27044 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential NULL pointer dereferences in 'dcn10_set_output_transfer_func()' The 'stream' pointer is used in dcn10_set_output_transfer_func() before the check if 'stream' i | 0.3% | — |
| CVE-2024-26988 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: init/main.c: Fix potential static_command_line memory overflow We allocate memory of size 'xlen + strlen(boot_command_line) + 1' for static_command_line, but the strings copied into static_c | 0.3% | — |
| CVE-2024-26903 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security During our fuzz testing of the connection and disconnection process at the RFCOMM layer, we discovered this bug. By comparing t | 0.3% | — |
| CVE-2024-26840 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix memory leak in cachefiles_add_cache() The following memory leak was reported after unbinding /dev/cachefiles: =============================================================== | 0.3% | — |