IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-6317 HIGH 8.8 google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6316 HIGH 8.8 google chrome Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-63093 HIGH 8.8 anysphere cursor Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted reposi 0.6%
CVE-2026-6307 HIGH 8.8 google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6306 HIGH 8.8 google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) 0.3%
CVE-2026-6305 HIGH 8.8 google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) 0.3%
CVE-2026-63046 HIGH 8.8 apache inlong Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issu 0.3%
CVE-2026-63041 HIGH 8.8 apache apisix Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitis 0.5%
CVE-2026-6303 HIGH 8.8 google chrome Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6302 HIGH 8.8 google chrome Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6301 HIGH 8.8 google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.4%
CVE-2026-6300 HIGH 8.8 google chrome Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-6299 HIGH 8.8 google chrome Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2026-62913 HIGH 8.8 microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-62872 HIGH 8.8 microsoft .net_framework Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-62870 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62869 HIGH 8.8 microsoft entra_id Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. 0.8%
CVE-2026-62827 HIGH 8.8 microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-62824 HIGH 8.8 microsoft windows_10_1607 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62823 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. 0.7%
CVE-2026-62822 HIGH 8.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62818 HIGH 8.8 microsoft windows_10_1607 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. 1.0%
CVE-2026-62817 HIGH 8.8 microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. 0.7%
CVE-2026-62816 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. 0.4%
CVE-2026-62800 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. 0.9%