57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70311 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68815 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68811 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68810 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68807 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68803 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64920 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64919 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64915 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64912 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64908 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64906 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64905 | HIGH 7.8 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64904 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63533 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63527 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-5877 | HIGH 8.8 | google chrome Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5872 | HIGH 8.8 | google chrome Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-5870 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-5866 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-5862 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-5861 | HIGH 8.8 | google chrome Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-50459 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48575 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-48570 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0.3% | — |