IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.588 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-5283 MED 6.5 google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-5282 HIGH 8.1 google chrome Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-5280 HIGH 8.8 google chrome Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-5279 HIGH 8.8 google chrome Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-5278 HIGH 8.8 google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-5277 HIGH 7.5 google chrome Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-52760 MED 6.1 apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic 0.5%
CVE-2026-5276 MED 6.5 google chrome Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-5275 HIGH 8.8 google chrome Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-5274 HIGH 8.8 google chrome Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-5273 MED 6.3 google chrome Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-5272 HIGH 8.8 google chrome Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.5%
CVE-2026-52680 CRIT 9.8 apache kyuubi Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and 0.7%
CVE-2026-50750 HIGH 7.5 apache activemq Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without se 0.5%
CVE-2026-50749 MED 6.5 apache answer Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. 0.3%
CVE-2026-50734 HIGH 7.5 apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. 0.5%
CVE-2026-50697 HIGH 7.8 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50696 HIGH 7.5 microsoft windows_10_1809 Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50695 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50694 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-50692 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50690 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50689 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50688 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1.7%
CVE-2026-50687 HIGH 8.8 microsoft windows_11_24h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%