58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-21236 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21232 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-21231 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2026-2123 | HIGH 7.8 | microfocus operations_agent A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsul | 0.1% | — |
| CVE-2026-21224 | HIGH 7.8 | microsoft azure_connected_machine_agent Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20957 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-20956 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-20955 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-20951 | HIGH 7.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2026-20950 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-20949 | HIGH 7.8 | microsoft 365_apps Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |
| CVE-2026-20948 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-20946 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2026-20941 | HIGH 7.8 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20940 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20938 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20930 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-20924 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20923 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1.1% | — |
| CVE-2026-20920 | HIGH 7.8 | microsoft windows_11_23h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20918 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20877 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20874 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20873 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |