IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-58540 HIGH 7.8 microsoft windows_10_1607 Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-57107 HIGH 7.8 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-57088 HIGH 7.8 microsoft windows_10_1809 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55014 HIGH 7.8 microsoft remote_help Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55006 HIGH 7.8 microsoft exchange_server Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-55001 HIGH 7.8 microsoft windows_10_1607 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50465 HIGH 7.1 microsoft windows_11_24h2 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-50423 HIGH 7.8 microsoft windows_10_21h2 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50405 HIGH 7.8 microsoft windows_10_1607 Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50391 HIGH 7.8 microsoft windows_10_1607 Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50373 HIGH 7.8 microsoft windows_10_1809 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50351 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50346 HIGH 7.8 microsoft windows_10_1607 Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50344 HIGH 7.8 microsoft windows_10_1607 Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50343 HIGH 7.8 microsoft windows_10_1809 Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50342 HIGH 8.8 microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50335 HIGH 7.8 microsoft windows_10_1809 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50333 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50311 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49170 HIGH 7.8 microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-48581 HIGH 7.8 microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-43215 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lo 0.3%
CVE-2026-43198 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is 0.3%
CVE-2026-40409 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.3%
CVE-2026-40408 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.3%