57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
57.044 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50311 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50309 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-50308 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-50306 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50305 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50301 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-50293 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49808 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49800 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49797 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-49796 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-49793 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-49792 | HIGH 7.8 | microsoft windows_10_1607 Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-49783 | HIGH 7.8 | microsoft windows_10_1607 Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-49745 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which resu | 0.1% | — |
| CVE-2026-49744 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow p | 0.1% | — |
| CVE-2026-49743 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driv | 0.1% | — |
| CVE-2026-49176 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-49175 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49173 | HIGH 7.8 | microsoft windows_11_26h1 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49170 | HIGH 7.8 | microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49166 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49161 | HIGH 7.8 | microsoft pc_manager Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. | 0.2% | — |
| CVE-2026-48583 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48581 | HIGH 7.8 | microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | 0.3% | — |