56.713 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.713 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-70322 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70321 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2026-70320 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70319 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70318 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70317 | MED 5.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70316 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70315 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-70314 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-70313 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-70312 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-70311 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-70310 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-70307 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70306 | CRIT 9.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-70304 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70130 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-69851 | CRIT 9.9 | microsoft entra_id Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-69836 | CRIT 10.0 | microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | 1.6% | — |
| CVE-2026-69558 | HIGH 8.6 | microsoft partner_center Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-69555 | CRIT 10.0 | microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69550 | MED 6.5 | microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-69543 | HIGH 8.5 | microsoft azure_virtual_machines Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | 0.3% | — |
| CVE-2026-69519 | HIGH 8.6 | microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-69414 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We wi | 0.6% | — |