58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50405 | HIGH 7.8 | microsoft windows_10_1607 Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50391 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50373 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50351 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50346 | HIGH 7.8 | microsoft windows_10_1607 Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50344 | HIGH 7.8 | microsoft windows_10_1607 Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50343 | HIGH 7.8 | microsoft windows_10_1809 Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50342 | HIGH 8.8 | microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50335 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50333 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50311 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-49170 | HIGH 7.8 | microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48581 | HIGH 7.8 | microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-47837 | MED 6.8 | vmware spring_cloud_config Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 | 0.3% | — |
| CVE-2026-43215 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lo | 0.3% | — |
| CVE-2026-43198 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is | 0.3% | — |
| CVE-2026-40409 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40408 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34693 | HIGH 8.0 | adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevat | 0.3% | — |
| CVE-2026-34333 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27919 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27915 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27907 | HIGH 7.8 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26180 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26163 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |