57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-12904 | MED 5.5 | amd radeon_software Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure. | 0.2% | — |
| CVE-2026-9926 | HIGH 8.3 | google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9924 | HIGH 8.3 | google chrome Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-83955 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-7929 | HIGH 7.5 | google chrome Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-77904 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73015 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73011 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73007 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73002 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-71378 | MED 4.6 | apache wicket ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy, FetchMetadataResourceIsolationPolicy, was deri | 0.2% | — |
| CVE-2026-71334 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69293 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-68875 | HIGH 7.8 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. | 0.2% | — |
| CVE-2026-68832 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62726 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62724 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62723 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61939 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61938 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61366 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61346 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50472 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42978 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.2% | — |