56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-5915 | HIGH 8.1 | google chrome Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-5914 | HIGH 8.8 | google chrome Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-59138 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | 1.0% | — |
| CVE-2026-59137 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59136 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59135 | MED 5.5 | microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-59134 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-59133 | HIGH 8.8 | microsoft windows_app Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-59132 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.3% | — |
| CVE-2026-59131 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-59130 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-5913 | HIGH 8.1 | google chrome Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-59128 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-59127 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-59126 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59124 | CRIT 9.8 | microsoft windows_app Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2026-59122 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-5912 | HIGH 8.8 | google chrome Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-59119 | HIGH 7.3 | microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-59118 | CRIT 9.3 | microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-59117 | HIGH 7.5 | microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-5911 | MED 4.3 | google chrome Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |