57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-58540 | HIGH 7.8 | microsoft windows_10_1607 Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-57107 | HIGH 7.8 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-57088 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-55014 | HIGH 7.8 | microsoft remote_help Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-55006 | HIGH 7.8 | microsoft exchange_server Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-55001 | HIGH 7.8 | microsoft windows_10_1607 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50465 | HIGH 7.1 | microsoft windows_11_24h2 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 0.3% | — |
| CVE-2026-50423 | HIGH 7.8 | microsoft windows_10_21h2 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50405 | HIGH 7.8 | microsoft windows_10_1607 Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50391 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50373 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50351 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50346 | HIGH 7.8 | microsoft windows_10_1607 Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50344 | HIGH 7.8 | microsoft windows_10_1607 Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50343 | HIGH 7.8 | microsoft windows_10_1809 Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50342 | HIGH 8.8 | microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50335 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50333 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50311 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49170 | HIGH 7.8 | microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48581 | HIGH 7.8 | microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-43215 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lo | 0.3% | — |
| CVE-2026-43198 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is | 0.3% | — |
| CVE-2026-40409 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40408 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |