56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.794 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-9975 | HIGH 8.3 | google chrome Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9970 | HIGH 8.3 | google chrome Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9966 | HIGH 8.3 | google chrome Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9954 | HIGH 7.5 | google chrome Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9905 | HIGH 8.3 | google chrome Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9890 | HIGH 8.3 | google chrome Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-8510 | HIGH 7.5 | google chrome Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-79126 | MED 5.9 | google chrome Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-66053 | MED 5.9 | apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603 | 0.2% | — |
| CVE-2026-65779 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65778 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65678 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62777 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58527 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58526 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-54991 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-54107 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50676 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50673 | HIGH 7.8 | microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50667 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50440 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50378 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50321 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50317 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42976 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | 0.2% | — |