58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-27920 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27919 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27918 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27916 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27915 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27914 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2026-27911 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27910 | HIGH 7.8 | microsoft windows_10_1607 Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27909 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | 1.8% | — |
| CVE-2026-27907 | HIGH 7.8 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-27784 | HIGH 7.8 | f5 nginx_open_source The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only | 1.0% | — |
| CVE-2026-27313 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.2% | — |
| CVE-2026-27312 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.3% | — |
| CVE-2026-27311 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.3% | — |
| CVE-2026-27310 | HIGH 7.8 | adobe bridge Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o | 0.3% | — |
| CVE-2026-27309 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m | 0.2% | — |
| CVE-2026-27298 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us | 0.2% | — |
| CVE-2026-27297 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.2% | — |
| CVE-2026-27296 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.2% | — |
| CVE-2026-27295 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open | 0.2% | — |
| CVE-2026-27294 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute c | 0.2% | — |
| CVE-2026-27293 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0.2% | — |
| CVE-2026-27292 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 0.2% | — |
| CVE-2026-27287 | HIGH 7.8 | adobe incopy InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code | 0.2% | — |
| CVE-2026-27284 | HIGH 7.8 | adobe indesign InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to exe | 0.2% | — |