56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-70348 | MED 5.5 | microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-70347 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70346 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70345 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-70344 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70340 | HIGH 8.1 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-70339 | MED 5.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.2% | — |
| CVE-2026-70338 | HIGH 7.8 | microsoft powershell Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-70337 | HIGH 8.8 | microsoft powershell Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-70336 | HIGH 8.8 | microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-70332 | CRIT 9.6 | microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-70330 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70329 | HIGH 8.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-70328 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70327 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70326 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-70325 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70324 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-70323 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70322 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70321 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2026-70320 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70319 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70318 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.4% | — |