56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.966 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-68793 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-68792 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-66807 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-66804 | HIGH 7.8 | microsoft windows_10_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 5.3% | — |
| CVE-2026-66799 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65814 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65810 | HIGH 7.8 | microsoft .net_framework Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65790 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65787 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65786 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65775 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2026-65774 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65773 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65673 | HIGH 7.8 | microsoft entra_connect Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65672 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65671 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65664 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-65661 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-65657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-65656 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-65099 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of | 0.7% | — |
| CVE-2026-65096 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosur | 0.7% | — |
| CVE-2026-65090 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial | 0.7% | — |
| CVE-2026-65089 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and | 0.7% | — |
| CVE-2026-64920 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |