IT
57.961 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.961 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-69817 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69816 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69814 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69567 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69422 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69413 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69333 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69287 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68825 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65814 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62694 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-5283 MED 6.5 google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-43334 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements before building the pairing response smp_cmd_pairing_req() currently builds the pairing response from the initiator auth_req before enforcin 0.3%
CVE-2026-32087 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-31513 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot reported a KASAN stack-out-of-bounds read in l2cap_build_cmd() that is triggered by a malformed Enhanced Credit 0.3%
CVE-2026-26165 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-2321 HIGH 8.8 google chrome Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2026-21280 HIGH 8.6 adobe illustrator Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as pr 0.3%
CVE-2026-20276 HIGH 8.6 cisco ios_xr As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte 0.3%
CVE-2026-11664 HIGH 8.8 google chrome Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-11659 CRIT 9.6 google chrome Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-11638 CRIT 9.6 google chrome Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-11634 CRIT 9.6 google chrome Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-11630 HIGH 8.8 google chrome Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-10016 HIGH 8.8 google chrome Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%