IT
57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.613 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-33115 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-33114 HIGH 8.4 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32221 HIGH 8.4 microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32190 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32162 HIGH 8.4 microsoft windows_10_1809 Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. 1.9%
CVE-2026-32091 HIGH 8.4 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. 0.2%
CVE-2026-26113 HIGH 8.4 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-26110 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-26109 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-23172 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow in RX path When receiving data in the DPMAIF RX path, the t7xx_dpmaif_set_frag_to_skb() function adds page fragments to an skb without chec 0.1%
CVE-2026-20953 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-20952 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-20944 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-17877 HIGH 8.4 google chrome Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) 0.1%
CVE-2025-69627 HIGH 8.4 gonitro nitro_pdf_pro Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is s 0.2%
CVE-2025-66516 HIGH 8.4 apache tika Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers th 87.7%
CVE-2025-6504 HIGH 8.4 progress hybrid_data_pipeline In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whiteli 0.2%
CVE-2025-64671 HIGH 8.4 microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-64298 HIGH 8.4 mirion biodose\/nmis NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access 0.2%
CVE-2025-62557 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-62554 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59974 HIGH 8.4 juniper space_security_director An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of oth 0.4%
CVE-2025-59236 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-54988 HIGH 8.4 apache tika Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitiv 37.7%
CVE-2025-54910 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%