IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-5915 HIGH 8.1 google chrome Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) 0.2%
CVE-2026-5914 HIGH 8.8 google chrome Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) 0.2%
CVE-2026-59138 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. 1.0%
CVE-2026-59137 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59136 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59135 MED 5.5 microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-59134 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-59133 HIGH 8.8 microsoft windows_app Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-59132 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. 1.3%
CVE-2026-59131 MED 5.6 microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-59130 MED 5.6 microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-5913 HIGH 8.1 google chrome Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) 0.2%
CVE-2026-59128 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59127 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59126 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-59125 HIGH 7.0 microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-59124 CRIT 9.8 microsoft windows_app Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. 1.7%
CVE-2026-59122 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-5912 HIGH 8.8 google chrome Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) 0.2%
CVE-2026-59119 HIGH 7.3 microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-59118 CRIT 9.3 microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-59117 HIGH 7.5 microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-59115 CRIT 9.9 microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-59113 HIGH 8.8 microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-5911 MED 4.3 google chrome Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) 0.2%