57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-42978 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42977 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42976 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42916 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42910 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42905 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2026-42902 | HIGH 7.8 | microsoft powertoys Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42896 | HIGH 7.8 | microsoft windows_11_24h2 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42837 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42834 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-42831 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-42829 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-42828 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41702 | HIGH 7.8 | vmware fusion VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to roo | 0.1% | — |
| CVE-2026-41611 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-41154 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB | 0.2% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0.4% | — |
| CVE-2026-41095 | HIGH 7.8 | microsoft windows_server_2012 Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41092 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41091 | HIGH 7.8 | microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 8.2% | |
| CVE-2026-41088 | HIGH 7.8 | microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40952 | HIGH 7.8 | absolute secure_access CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is | 0.1% | — |
| CVE-2026-40419 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40418 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40417 | HIGH 7.8 | microsoft dynamics_365_business_central Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | 0.3% | — |