57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-42831 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-42829 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-42828 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41702 | HIGH 7.8 | vmware fusion VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to roo | 0.1% | — |
| CVE-2026-41611 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-41154 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB | 0.2% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0.4% | — |
| CVE-2026-41095 | HIGH 7.8 | microsoft windows_server_2012 Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41092 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41091 | HIGH 7.8 | microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 8.2% | |
| CVE-2026-41088 | HIGH 7.8 | microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40952 | HIGH 7.8 | absolute secure_access CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is | 0.1% | — |
| CVE-2026-40419 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40418 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40417 | HIGH 7.8 | microsoft dynamics_365_business_central Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40409 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40408 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40407 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40404 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-40399 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40398 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2026-40397 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40382 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-40381 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-40377 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. | 0.3% | — |