57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-61348 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2026-61346 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59126 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59122 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58637 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58629 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58619 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58598 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58544 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58526 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-57093 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-56187 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-56183 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-56173 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-54996 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-54989 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-54129 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-54111 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-53329 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_vector_reserve() computes the allocation size as "capacity * vector->struct_size" using uint32_t arithmetic, whi | 0.1% | — |
| CVE-2026-50674 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50672 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50669 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50658 | HIGH 7.0 | microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50526 | HIGH 7.0 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | 0.2% | — |