58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2007-3036 | MED 6.9 | microsoft windows_2003_server Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain se | 2.4% | — |
| CVE-2007-1973 | MED 6.9 | microsoft windows_nt Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206. | 1.5% | — |
| CVE-2007-1217 | MED 6.9 | linux linux_kernel Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet. | 0.4% | — |
| CVE-2007-0997 | MED 6.9 | linux linux_kernel Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors r | 0.2% | — |
| CVE-2007-0005 | MED 6.9 | omnikey.aaitg omnikey_cardman_4040 Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges. | 0.6% | — |
| CVE-2006-6696 | MED 6.9 | microsoft windows_2000 Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime | 3.4% | — |
| CVE-2006-0038 | MED 6.9 | linux linux_kernel Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function. | 0.4% | — |
| CVE-2005-0767 | MED 6.9 | linux linux_kernel Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root. | 0.4% | — |
| CVE-2005-0001 | MED 6.9 | linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor | 0.5% | — |
| CVE-2026-98163 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime | 0.2% | — |
| CVE-2026-85360 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83999 | HIGH 7.0 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-83940 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-81389 | HIGH 7.0 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-80093 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-78464 | HIGH 7.0 | microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-78457 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77905 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77899 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77897 | HIGH 7.0 | microsoft power_automate_for_desktop Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77894 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77485 | HIGH 7.0 | microsoft sql_server_2017 Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-73022 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-73005 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-73003 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0.3% | — |