IT
58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-43044 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: caam - fix DMA corruption on long hmac keys When a key longer than block size is supplied, it is copied and then hashed into the real key. The memory allocated for the copy needs to 0.2% —
CVE-2026-43033 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bit 0.2% —
CVE-2026-43030 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold->reg->range == BEYOND_PKT_END && rcur->reg->range == N regsafe() may return true which may lead to current state with valid packet rang 0.2% —
CVE-2026-43027 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy() to remove expectations belonging to the helper being unreg 0.2% —
CVE-2026-43023 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() checks sk_state and sk_type without holding the socket lock. Two concurrent connect() syscalls on the same socket 0.1% —
CVE-2026-43020 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided enc_size and later uses it to size fixed-size stack operations when replying to LE LTK requests. A 0.2% —
CVE-2026-43019 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup and field access must be covered by hdev lock in set_cig_params_sync, otherwise it's possible it is freed concur 0.2% —
CVE-2026-43016 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready(). syzbot reported use-after-free of AF_UNIX socket's sk->sk_socket in sk_psock_verdict_data_ready(). [0] In 0.2% —
CVE-2026-43015 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: macb: fix clk handling on PCI glue driver removal platform_device_unregister() may still want to use the registered clks during runtime resume callback. Note that there is a commit d82 0.2% —
CVE-2026-43009 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) 0.2% —
CVE-2026-43007 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Handle DBC deactivation if the owner went away When a DBC is released, the device sends a QAIC_TRANS_DEACTIVATE_FROM_DEV transaction to the host over the QAIC_CONTROL MHI channel 0.2% —
CVE-2026-42991 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-42989 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2026-42986 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42983 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42982 HIGH 7.8 microsoft windows_10_1607 Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42980 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42979 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-42978 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-42977 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-42976 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42916 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42910 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42905 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-42902 HIGH 7.8 microsoft powertoys Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. 0.3% —