58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-72946 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72944 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72941 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72929 | HIGH 7.8 | microsoft windows_11_23h2 Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-72255 | HIGH 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst The br_netfilter fake rtable is embedded in struct net_bridge and is attached to bridged packets with skb_dst_set_noref(). | 0.2% | — |
| CVE-2026-71399 | HIGH 7.8 | adobe xd Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interacti | 0.3% | — |
| CVE-2026-71345 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-71343 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-71337 | HIGH 7.8 | microsoft windows_10_21h2 Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71334 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70584 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70583 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70581 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70574 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70572 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70569 | HIGH 7.8 | microsoft windows_11_23h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70564 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70354 | HIGH 7.8 | microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-70347 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70346 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70345 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70344 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70338 | HIGH 7.8 | microsoft powershell Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-70334 | HIGH 7.8 | microsoft visual_studio_code Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |