58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69564 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69563 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69560 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69540 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69517 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69501 | HIGH 7.0 | microsoft windows_10_21h2 Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69500 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69473 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69466 | HIGH 7.0 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69448 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69441 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69440 | HIGH 7.0 | microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69430 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69422 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69413 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69410 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69404 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69398 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69394 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69388 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69385 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69383 | HIGH 7.0 | microsoft windows_11_23h2 External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69379 | HIGH 7.0 | microsoft windows_11_23h2 Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69362 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69341 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. | 0.3% | — |