57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-20827 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20826 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20825 | MED 4.4 | microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-20824 | MED 5.5 | microsoft windows_10_1607 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | 0.9% | — |
| CVE-2026-20823 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20822 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20821 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20820 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2026-20819 | MED 5.5 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-20818 | MED 6.2 | microsoft windows_server_2016 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2026-20817 | HIGH 7.8 | microsoft windows_10_21h2 Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 5.4% | — |
| CVE-2026-20816 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | 2.5% | — |
| CVE-2026-20815 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20814 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20812 | MED 6.5 | microsoft windows_10_1607 Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | 1.1% | — |
| CVE-2026-20811 | HIGH 7.8 | microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20810 | HIGH 7.8 | microsoft windows_10_1809 Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-20809 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20808 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-20806 | MED 5.5 | microsoft windows_10_1809 Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-20804 | HIGH 7.7 | microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-20803 | HIGH 7.2 | microsoft sql_server_2022 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2026-20732 | LOW 3.1 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.2% | — |
| CVE-2026-20730 | LOW 3.3 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.1% | — |
| CVE-2026-20355 | MED 5.9 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities a | 0.1% | — |