58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-78502 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-78453 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-78441 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-77911 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-77896 | MED 6.5 | microsoft windows_10_1607 Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. | 0.7% | — |
| CVE-2026-75880 | MED 6.5 | apache artemis An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apac | 0.7% | — |
| CVE-2026-73239 | MED 6.5 | apache allura Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | 0.6% | — |
| CVE-2026-73029 | MED 6.5 | microsoft sql_server_2019 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-72977 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-72975 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72974 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72956 | MED 6.5 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72942 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72939 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-72938 | MED 6.5 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70328 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70327 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70105 | MED 6.5 | microsoft microsoft_365 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-70019 | MED 6.5 | microsoft windows_11_23h2 Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-69839 | MED 6.5 | microsoft windows_10_1607 Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-69781 | MED 6.5 | microsoft windows_11_24h2 Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69739 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69734 | MED 6.5 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69719 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69683 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.8% | — |