IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-52935 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a single in-flight transmit in ctx->partial. Before building a new sk_msg, espintcp_sendmsg() first tries to flush tha 0.2%
CVE-2026-52933 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: i 0.1%
CVE-2026-52927 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The function compat_mtw_from_user() converts ebtables extensions from 32-bit user structures to kernel native str 0.1%
CVE-2026-52923 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request 0.2%
CVE-2026-52919 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally decrements the "sending" atomic counter. If multiple paths (e.g. timeout, user cancel, 0.1%
CVE-2026-52912 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only h 0.1%
CVE-2026-52910 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog and replaces it with a n 0.1%
CVE-2026-52909 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip 0.1%
CVE-2026-52908 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the 0.1%
CVE-2026-52907 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change these comparisons from > vs >= to avoid accessing one element beyond the end of the arrays. While at it, use ARRAY_SIZE instead of the _MAX 0.1%
CVE-2026-50697 HIGH 7.8 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-50689 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50688 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50679 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50677 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50676 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50675 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-50673 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50667 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50665 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-50656 HIGH 7.8 microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". 11.4%
CVE-2026-50655 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-50650 HIGH 7.8 microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-50649 HIGH 7.8 microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. 0.9%
CVE-2026-50646 HIGH 7.8 microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. 1.0%