58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69335 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69333 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69331 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69319 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69311 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69310 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69309 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69300 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69299 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69287 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69281 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69280 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69279 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68884 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68847 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68840 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-68837 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68825 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68824 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-68820 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 6.2% | |
| CVE-2026-6851 | HIGH 7.0 | bitdefender internet_security An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race condit | 0.1% | — |
| CVE-2026-65788 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 1.7% | — |
| CVE-2026-65783 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65782 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65781 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |