IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-6309 HIGH 8.3 google chrome Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6308 HIGH 7.5 google chrome Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-63071 CRIT 9.8 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affect 0.4%
CVE-2026-6307 HIGH 8.8 google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6306 HIGH 8.8 google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) 0.3%
CVE-2026-6305 HIGH 8.8 google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) 0.3%
CVE-2026-6304 HIGH 8.3 google chrome Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6303 HIGH 8.8 google chrome Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6302 HIGH 8.8 google chrome Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6301 HIGH 8.8 google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6300 HIGH 8.8 google chrome Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6299 HIGH 8.8 google chrome Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-6298 MED 4.3 google chrome Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-6297 HIGH 8.3 google chrome Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.2%
CVE-2026-6296 CRIT 9.6 google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-62918 HIGH 7.5 microsoft teams Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2026-62917 MED 4.6 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-62915 MED 6.5 microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. 0.5%
CVE-2026-62914 HIGH 7.3 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2026-62913 HIGH 8.8 microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. 0.6%
CVE-2026-62912 MED 6.5 microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. 1.3%
CVE-2026-62911 HIGH 8.0 microsoft exchange_server Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-62910 HIGH 7.2 microsoft exchange_server Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-62909 HIGH 7.8 microsoft .net Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62908 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. 0.2%