57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50325 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50323 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50322 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50307 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50297 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50296 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49806 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49805 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49803 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49802 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49784 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49183 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49162 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48572 | HIGH 7.0 | microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-48571 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-47648 | HIGH 7.0 | microsoft windows_10_1607 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-47293 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-46309 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise Add validation in xe_vm_madvise_ioctl() to reject PAT indices with XE_COH_NONE coherency mode when applied to CPU cach | 0.1% | — |
| CVE-2026-46299 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super() hfsplus_fill_super() calls hfs_find_init() to initialize a search structure, which acquires tree->tree_lock. If the subsequent call to hf | 0.1% | — |
| CVE-2026-46164 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_group() error path When kobject_init_and_add() fails, the call chain is: create_space_info_sub_group() -> btrfs_sysfs_add_space_info_type() - | 0.1% | — |
| CVE-2026-46154 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters scx_group_set_{weight,idle,bandwidth}() cache scx_root before acquiring scx_cgroup_ops_rwsem, so the pointer can be stal | 0.1% | — |
| CVE-2026-46029 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm/slab: return NULL early from kmalloc_nolock() in NMI on UP On UP kernels (!CONFIG_SMP), spin_trylock() is a no-op that unconditionally succeeds even when the lock is already held. As a re | 0.1% | — |
| CVE-2026-45653 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45640 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-45603 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |