57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-40409 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40408 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40407 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40404 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40399 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40398 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2026-40397 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40382 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-40381 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-40377 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40369 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4.7% | — |
| CVE-2026-40362 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-40360 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-40359 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-40048 | HIGH 7.8 | apache camel The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.K | 0.2% | — |
| CVE-2026-3779 | HIGH 7.8 | foxit pdf_editor The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary cod | 0.3% | — |
| CVE-2026-3775 | HIGH 7.8 | foxit pdf_editor The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be | 0.3% | — |
| CVE-2026-35558 | HIGH 7.8 | amazon athena_odbc Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that | 0.3% | — |
| CVE-2026-35421 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-35420 | HIGH 7.8 | microsoft windows_server_2012 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-35418 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-35417 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-35415 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34708 | HIGH 7.8 | adobe incopy InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.2% | — |
| CVE-2026-34707 | HIGH 7.8 | adobe incopy InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope | 0.2% | — |