IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-50329 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-50327 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-50326 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-50318 HIGH 7.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-50315 HIGH 7.8 microsoft windows_11_24h2 Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-50309 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-50306 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-50293 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-49800 HIGH 7.8 microsoft windows_10_1809 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-49795 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-49793 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-49792 HIGH 7.8 microsoft windows_10_1607 Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3% —
CVE-2026-49783 HIGH 7.8 microsoft windows_10_1607 Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3% —
CVE-2026-49175 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-49173 HIGH 7.8 microsoft windows_11_26h1 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-49166 HIGH 7.8 microsoft windows_11_24h2 Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-47635 HIGH 8.4 microsoft office_2024 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3% —
CVE-2026-45972 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double f 0.3% —
CVE-2026-42982 HIGH 7.8 microsoft windows_10_1607 Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3% —
CVE-2026-10986 HIGH 8.8 google chrome Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High) 0.3% —
CVE-2026-10978 HIGH 8.8 google chrome Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) 0.3% —
CVE-2026-0298 HIGH 8.1 paloaltonetworks globalprotect An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM 0.3% —
CVE-2025-69267 MED 6.5 broadcom dx_netops_spectrum Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. 0.3% —
CVE-2025-6505 HIGH 8.1 progress hybrid_data_pipeline Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client imper 0.3% —
CVE-2025-61819 HIGH 7.8 adobe photoshop Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus 0.3% —