IT
57.136 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.136 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-70324 HIGH 8.8 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-70321 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.3%
CVE-2026-69764 HIGH 8.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69759 HIGH 8.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69722 HIGH 8.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69686 HIGH 8.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69671 HIGH 8.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69556 HIGH 8.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69320 HIGH 8.8 microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-67587 HIGH 8.8 apache airflow Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserializati 0.6%
CVE-2026-67305 HIGH 8.8 freerdp freerdp FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP 0.5%
CVE-2026-66842 HIGH 8.8 BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacke 0.2%
CVE-2026-66808 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.1%
CVE-2026-66805 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.5%
CVE-2026-65815 HIGH 8.8 microsoft dynamics_365 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-65811 HIGH 8.8 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-65807 HIGH 8.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-65768 HIGH 8.8 microsoft teams Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-65767 HIGH 8.8 microsoft teams Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-65668 HIGH 8.8 microsoft purview_ediscovery Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-65665 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.8%
CVE-2026-65663 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.4%
CVE-2026-65660 HIGH 8.8 microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.8%
CVE-2026-65658 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.4%
CVE-2026-64921 HIGH 8.8 microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 1.0%