57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69722 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69686 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69671 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69629 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69556 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69442 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-58594 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57981 | HIGH 8.8 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57974 | HIGH 8.8 | microsoft edge_chromium Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57102 | HIGH 8.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-57094 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57090 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-56645 | HIGH 8.8 | microsoft edge_chromium Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-54990 | CRIT 9.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50474 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50380 | CRIT 9.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-55238 | HIGH 7.5 | microsoft dynamics_365 Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | 0.8% | — |
| CVE-2025-21185 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35275 | MED 6.6 | fortinet fortianalyzer A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http request | 0.8% | — |
| CVE-2024-26188 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.8% | — |
| CVE-2023-37579 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut | 0.8% | — |
| CVE-2023-30428 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Broke | 0.8% | — |
| CVE-2022-22409 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592. | 0.8% | — |
| CVE-2021-39019 | MED 6.5 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. | 0.8% | — |
| CVE-2021-33034 | HIGH 7.8 | debian debian_linux In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. | 0.8% | — |