57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-81947 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-81398 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-81397 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-81396 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-81388 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-81386 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-81353 | HIGH 7.8 | microsoft heif_image_extension Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-80161 | HIGH 7.8 | adobe acrobat Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary cod | 0.2% | — |
| CVE-2026-80075 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-7994 | HIGH 7.8 | google chrome Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2026-79909 | HIGH 7.8 | adobe acrobat Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2026-79908 | HIGH 7.8 | adobe acrobat Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2026-79907 | HIGH 7.8 | adobe acrobat Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2026-7990 | HIGH 7.8 | google chrome Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2026-7925 | HIGH 7.8 | google chrome Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) | 0.1% | — |
| CVE-2026-78604 | HIGH 7.8 | elastic elastic_agent Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent serv | 0.1% | — |
| CVE-2026-78448 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-78447 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77904 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-77500 | HIGH 7.8 | microsoft windows_10_1607 Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-77489 | HIGH 7.8 | microsoft windows_10_1607 Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-7639 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a | 0.2% | — |
| CVE-2026-75863 | HIGH 7.8 | adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2026-75862 | HIGH 7.8 | adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |
| CVE-2026-75771 | HIGH 7.8 | adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0.2% | — |