57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-45656 | HIGH 7.8 | microsoft windows_10_1607 Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2026-45645 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45643 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45638 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45637 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45636 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45605 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45600 | HIGH 7.8 | microsoft windows_11_24h2 Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45593 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45592 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45586 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. | 3.6% | — |
| CVE-2026-45490 | HIGH 7.8 | microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-45487 | HIGH 7.8 | microsoft windows_10_21h2 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-45486 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45475 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45471 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-45469 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45457 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45203 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in m | 0.1% | — |
| CVE-2026-45196 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation. | 0.1% | — |
| CVE-2026-45176 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Un | 0.1% | — |
| CVE-2026-45175 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumst | 0.1% | — |
| CVE-2026-45174 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | 0.1% | — |
| CVE-2026-44824 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44823 | HIGH 7.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |