IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.864 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-70314 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-70312 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-70310 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68813 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68809 MED 5.5 microsoft 365_apps Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68808 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68802 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68799 MED 5.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68797 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-66810 MED 5.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66809 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66806 MED 5.5 microsoft 365_apps Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-65784 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-65662 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-65088 MED 5.5 nvidia nemoclaw NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. 0.1%
CVE-2026-64917 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-64899 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-64297 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_extend_max_pages() module_extend_max_pages() calls kvrealloc() internally and returns -ENOMEM on allocation failure. The return value is neve 0.2%
CVE-2026-64295 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access The page_ext iteration API does not validate if the PFN still belongs to a valid section while advancing the 0.2%
CVE-2026-64294 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: do file ownership checks with the proper mount idmap Ever since idmapped mounts were introduced, inode ownership checks (for side-channel protection) in mincore() and madvise(MADV_PAGEOU 0.2%
CVE-2026-64292 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spinlock The veventq memory allocation happens inside the spinlock. Given its depth is decided by the user space, this leaves a vulnerability, 0.2%
CVE-2026-64291 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Set veventq_depth upper bound iommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with an upper bound at U32_MAX. This leaves a vulnerability where userspace can a 0.2%
CVE-2026-64290 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Break the loop on failure in iommufd_fault_fops_read() On a copy_to_user() failure inside the inner list_for_each_entry, only the inner loop breaks; the outer while re-fetches the j 0.2%
CVE-2026-64289 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Set upper bounds on cache invalidation entry_num and entry_len iommufd_hwpt_invalidate() takes a user-controlled entry_num and entry_len, each bounded only by U32_MAX. An entry_len 0.2%
CVE-2026-64288 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB VNCR TLB invalidation occurs from MMU notifiers or TLBI instructions, and either can race against a vcpu not being onlined yet (no ps 0.2%