56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-40466 | HIGH 8.8 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an | 4.8% | — |
| CVE-2026-40420 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-40403 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-40371 | HIGH 8.8 | microsoft dynamics_365 Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-40370 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-40365 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-40357 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.7% | — |
| CVE-2026-39998 | HIGH 8.8 | apache apisix Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrad | 0.7% | — |
| CVE-2026-39816 | HIGH 8.8 | apache nifi The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Scrip | 0.8% | — |
| CVE-2026-39815 | HIGH 8.8 | fortinet fortiddos-f A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests | 0.4% | — |
| CVE-2026-3936 | HIGH 8.8 | google chrome Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-3931 | HIGH 8.8 | google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-3926 | HIGH 8.8 | google chrome Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-3923 | HIGH 8.8 | google chrome Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3922 | HIGH 8.8 | google chrome Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3921 | HIGH 8.8 | google chrome Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3920 | HIGH 8.8 | google chrome Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3919 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3918 | HIGH 8.8 | google chrome Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3917 | HIGH 8.8 | google chrome Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3915 | HIGH 8.8 | google chrome Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-3914 | HIGH 8.8 | google chrome Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3913 | HIGH 8.8 | google chrome Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-3910 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 2.0% | |
| CVE-2026-3909 | HIGH 8.8 | google chrome Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 1.6% |