57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-71399 | HIGH 7.8 | adobe xd Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interacti | 0.2% | — |
| CVE-2026-71343 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-71337 | HIGH 7.8 | microsoft windows_10_21h2 Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71334 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-70581 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70572 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70569 | HIGH 7.8 | microsoft windows_11_23h2 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70564 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70354 | HIGH 7.8 | microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-70347 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70346 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70345 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-70344 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70338 | HIGH 7.8 | microsoft powershell Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-70334 | HIGH 7.8 | microsoft visual_studio_code Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-70313 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-70311 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-70289 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69921 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69907 | HIGH 7.8 | microsoft windows_10_1607 Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69900 | HIGH 7.8 | microsoft windows_10_21h2 Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69864 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-69844 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69841 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | 0.3% | — |