IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-78502 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-78453 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-77911 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-73239 MED 6.5 apache allura Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. 0.3%
CVE-2026-72977 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-72975 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-72974 MED 6.5 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-72956 MED 6.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-72938 MED 6.5 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-70328 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-70327 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-70105 MED 6.5 microsoft microsoft_365 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-69781 MED 6.5 microsoft windows_11_24h2 Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. 0.5%
CVE-2026-69739 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-69734 MED 6.5 microsoft 365_apps Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-69719 MED 6.5 microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-69683 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0.9%
CVE-2026-69636 MED 6.5 microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-69626 MED 6.5 microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-69550 MED 6.5 microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-69497 MED 6.5 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-69409 MED 6.5 microsoft sharepoint_server Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-6938 MED 6.5 ibm db2 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. 0.2%
CVE-2026-69297 MED 6.5 microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-68971 MED 6.5 apache airflow Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manag 0.3%