IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-45656 HIGH 7.8 microsoft windows_10_1607 Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-45645 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45643 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45638 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45637 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45636 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45605 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45600 HIGH 7.8 microsoft windows_11_24h2 Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45593 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45592 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45586 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2026-45490 HIGH 7.8 microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-45487 HIGH 7.8 microsoft windows_10_21h2 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-45486 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45475 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-45471 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-45469 HIGH 7.8 microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45457 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45203 HIGH 7.8 imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in m 0.1%
CVE-2026-45196 HIGH 7.8 imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation. 0.1%
CVE-2026-45176 HIGH 7.8 paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Un 0.1%
CVE-2026-45175 HIGH 7.8 paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumst 0.1%
CVE-2026-45174 HIGH 7.8 paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 0.1%
CVE-2026-44824 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-44823 HIGH 7.8 microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%