58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-48574 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-47646 | CRIT 9.3 | microsoft dynamics_365_customer_voice Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-47642 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-47631 | HIGH 8.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-47305 | HIGH 7.8 | microsoft visual_studio_2022 Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-47290 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45645 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45643 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45636 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45486 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45469 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45457 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44823 | HIGH 7.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44820 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44817 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44812 | HIGH 7.8 | microsoft excel Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44803 | HIGH 7.8 | microsoft excel Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-42913 | HIGH 7.5 | microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-42909 | HIGH 7.5 | microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-42831 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-40362 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-40360 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-40359 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-35421 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-33518 | CRIT 9.8 | esri portal_for_arcgis An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. | 0.5% | — |