56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.966 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-63803 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hdlc_ppp: sync per-proto timers before freeing hdlc state Each PPP control protocol (LCP/IPCP/IPV6CP) embedded in struct ppp registers a timer via timer_setup(). That struct ppp is the hdlc- | 0.1% | — |
| CVE-2026-63802 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix UAF in __blkcg_rstat_flush() When multiple blkgs in the same blkcg are released concurrently, a use-after-free can occur. The race happens when one blkg's __blkcg_rstat_flush | 0.1% | — |
| CVE-2026-63799 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path In mm_cid_fixup_cpus_to_tasks(), when rq->curr has the target mm and mm_cid.active is set, the CID is checked with cid_i | 0.2% | — |
| CVE-2026-63794 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path In sev_dbg_crypt(), the per-iteration transfer length is bounded by the source page offset (PAGE_SIZE - s_off) but not by the | 0.1% | — |
| CVE-2026-63793 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize volume label accesses Protect vol->volume_label with a mutex and snaphost the label before copy_to_user. This prevent a use-after-free when FS_IOC_SETFSLABEL replaces the vol | 0.2% | — |
| CVE-2026-63533 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63532 | HIGH 7.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63527 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63526 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-63525 | HIGH 7.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-63522 | HIGH 7.8 | microsoft azure_sql_database Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-63519 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-63518 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-63515 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-63513 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-62909 | HIGH 7.8 | microsoft .net Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62894 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62890 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-62888 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2026-62886 | HIGH 7.8 | microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-62885 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62880 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62877 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62876 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62871 | HIGH 7.8 | microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 0.4% | — |