56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-3544 | HIGH 8.8 | google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-35439 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-35436 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-35430 | HIGH 8.8 | microsoft azure_privileged_identity_management Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-3543 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3541 | HIGH 8.8 | google chrome Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3540 | HIGH 8.8 | google chrome Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3538 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-3537 | HIGH 8.8 | google chrome Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-3536 | HIGH 8.8 | google chrome Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-35337 | HIGH 8.8 | apache storm Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.r | 1.0% | — |
| CVE-2026-35152 | HIGH 8.8 | apache fineract A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authen | 3.3% | — |
| CVE-2026-34329 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-34197 | HIGH 8.8 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia | 97.2% | |
| CVE-2026-33858 | HIGH 8.8 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0.6% | — |
| CVE-2026-33785 | HIGH 8.8 | juniper junos A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, wit | 0.1% | — |
| CVE-2026-33120 | HIGH 8.8 | microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33112 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 32.7% | — |
| CVE-2026-33110 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-32225 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 1.2% | — |
| CVE-2026-32208 | HIGH 8.8 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-32207 | HIGH 8.8 | microsoft azure_machine_learning Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-32193 | HIGH 8.8 | microsoft azure_kubernetes_service Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-32171 | HIGH 8.8 | microsoft azure_logic_apps Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 0.4% | — |