57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-26174 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26173 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26166 | HIGH 7.0 | microsoft windows_11_23h2 Double free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26165 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26152 | HIGH 7.0 | microsoft windows_10_1607 Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-25184 | HIGH 7.0 | microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-25179 | HIGH 7.0 | microsoft windows_10_1607 Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-25178 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-25171 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-25170 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-25087 | HIGH 7.0 | apache arrow Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadi | 0.8% | — |
| CVE-2026-24296 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-24295 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-24285 | HIGH 7.0 | microsoft 365_copilot Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-23671 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-23668 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 3.6% | — |
| CVE-2026-23667 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-23454 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the H | 0.1% | — |
| CVE-2026-23294 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be accessed concurrently by multiple preemptible tasks on the same CPU. The original cod | 0.1% | — |
| CVE-2026-23195 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cgroup/dmem: avoid pool UAF An UAF issue was observed: BUG: KASAN: slab-use-after-free in page_counter_uncharge+0x65/0x150 Write of size 8 at addr ffff888106715440 by task insmod/527 CPU: | 0.1% | — |
| CVE-2026-23013 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback octep_vf_request_irqs() requests MSI-X queue IRQs with dev_id set to ioq_vector. If request_irq() fails part-way, the rollback | 0.2% | — |
| CVE-2026-21508 | HIGH 7.0 | microsoft windows_10_1607 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21253 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2026-21242 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21241 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 2.6% | — |