56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.966 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-64919 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64915 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64914 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-64912 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64911 | HIGH 7.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64910 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64909 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64908 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64907 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64906 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64905 | HIGH 7.8 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64904 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64903 | HIGH 7.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64898 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-64600 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, th | 0.5% | — |
| CVE-2026-64453 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: fix disconnect UAF in client teardown usbio_disconnect() walks usbio->cli_list in reverse and uninitializes each auxiliary device. auxiliary_device_uninit() drops the devic | 0.2% | — |
| CVE-2026-64449 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: bound slave read/write to the kern_buf size The SLAVE-path helpers buffer_to_user() and buffer_from_user() copy 'count' bytes into/out of the fixed-size kern_buf (size_buf | 0.1% | — |
| CVE-2026-64447 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and use-after-free in error paths In both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and then passed to ipu7_bus_initialize_device(), whi | 0.1% | — |
| CVE-2026-64446 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() supplicant_ie is a 256-byte array in struct security_priv. The WPA and WPA2 IE copy paths use: memcpy(padapter- | 0.2% | — |
| CVE-2026-64433 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete add_device_complete() runs from the hci_cmd_sync_work kworker, which holds only hci_req_sync_lock and *not* hci_dev_lock. | 0.2% | — |
| CVE-2026-64432 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns In the analysis pass of $LogFile journal replay, log_replay() copies LCNs from each action log record into an existing Di | 0.1% | — |
| CVE-2026-64431 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid calling post_write_mst_fixup() for invalid index_block ntfs_icx_ib_sync_write() calls post_write_mst_fixup() when ntfs_ib_write() returns an error, intending to restore the buffe | 0.1% | — |
| CVE-2026-64352 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Allow LPM map access from sleepable BPF programs trie_lookup_elem() annotates its rcu_dereference_check() walks with only rcu_read_lock_bh_held(). Because rcu_dereference_check(p, c) r | 0.2% | — |
| CVE-2026-64348 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: free iso schedules on failed submit EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in urb->hcpri | 0.2% | — |
| CVE-2026-64346 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: Fix use-after-free in gadget_match_driver The udc structure acts as the management structure for the gadget, but their lifecycles are decoupled. A race condition exists whe | 0.2% | — |