58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70313 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70311 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-70289 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69921 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69907 | HIGH 7.8 | microsoft windows_10_1607 Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69900 | HIGH 7.8 | microsoft windows_10_21h2 Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69864 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69844 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69841 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69822 | HIGH 7.8 | microsoft windows_10_1809 Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69821 | HIGH 7.8 | microsoft windows_10_1607 Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69801 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69799 | HIGH 7.8 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69790 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69787 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69785 | HIGH 7.8 | microsoft windows_10_1607 Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-69758 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69738 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69731 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69725 | HIGH 7.8 | microsoft windows_10_21h2 Double free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69720 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69709 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-69707 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69691 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69687 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | 0.3% | — |