58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.560 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20871 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | 4.2% | — |
| CVE-2026-20870 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20867 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20866 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20865 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20864 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-20861 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20860 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 8.4% | — |
| CVE-2026-20859 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20858 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20857 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20843 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 3.5% | — |
| CVE-2026-20841 | HIGH 7.8 | microsoft windows_notepad Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally. | 12.7% | — |
| CVE-2026-20840 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 4.7% | — |
| CVE-2026-20837 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2026-20832 | HIGH 7.8 | microsoft windows_10_1607 Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-20831 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20826 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20822 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20820 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2026-20817 | HIGH 7.8 | microsoft windows_10_21h2 Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 5.5% | — |
| CVE-2026-20816 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | 2.5% | — |
| CVE-2026-20811 | HIGH 7.8 | microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20810 | HIGH 7.8 | microsoft windows_10_1809 Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20809 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | 0.4% | — |