IT
56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.663 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-79138 CRIT 9.6 google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-7910 CRIT 9.6 google chrome Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-7908 CRIT 9.6 google chrome Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-79019 CRIT 9.6 google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-78989 CRIT 9.6 google chrome Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-7333 CRIT 9.6 google chrome Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-70332 CRIT 9.6 microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-69400 CRIT 9.6 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-6920 CRIT 9.6 google chrome Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-6919 CRIT 9.6 google chrome Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6296 CRIT 9.6 google chrome Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-62896 CRIT 9.6 microsoft teams Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2026-5874 CRIT 9.6 google chrome Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) 0.3%
CVE-2026-56161 CRIT 9.6 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. 0.4%
CVE-2026-55008 CRIT 9.6 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2026-5290 CRIT 9.6 google chrome Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-5289 CRIT 9.6 google chrome Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-5288 CRIT 9.6 google chrome Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-50380 CRIT 9.6 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-48582 CRIT 9.6 microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-48561 CRIT 9.6 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-48317 CRIT 9.6 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker coul 0.5%
CVE-2026-47281 CRIT 9.6 microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2026-42904 CRIT 9.6 microsoft windows_10_21h2 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. 0.4%
CVE-2026-41615 CRIT 9.6 microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. 0.6%