57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.825 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1731 | MED 5.5 | microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-1661 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0733 | HIGH 7.8 | microsoft windows_malicious_software_removal_tool An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Softw | 0.8% | — |
| CVE-2017-6601 | HIGH 7.1 | cisco firepower_extensible_operating_system A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection | 0.8% | — |
| CVE-2013-1860 | MED 6.9 | canonical ubuntu_linux Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wd | 0.8% | — |
| CVE-2007-4573 | HIGH 7.2 | linux linux_kernel The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain pri | 0.8% | — |
| CVE-2026-78512 | HIGH 8.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78511 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-72973 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-72972 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69764 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69759 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69722 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69686 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69671 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69556 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-58594 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57102 | HIGH 8.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-57094 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57090 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50474 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50380 | CRIT 9.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-54990 | CRIT 9.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57981 | HIGH 8.8 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57974 | HIGH 8.8 | microsoft edge_chromium Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |