56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-23226 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksm | 0.4% | — |
| CVE-2026-2321 | HIGH 8.8 | google chrome Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-23193 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In iscsit_dec_session_usage_count(), the function calls complete() while holding the sess->session_usage_lock. Sim | 0.2% | — |
| CVE-2026-2315 | HIGH 8.8 | google chrome Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 8.3% | — |
| CVE-2026-2314 | HIGH 8.8 | google chrome Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 4.2% | — |
| CVE-2026-2313 | HIGH 8.8 | google chrome Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 4.1% | — |
| CVE-2026-23098 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately freed without checking if nr_neigh->ax25 pointer is NULL. Therefore, if nr_neigh->ax25 is NULL, the ca | 0.2% | — |
| CVE-2026-22730 | HIGH 8.8 | vmware spring_ai A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. | 0.5% | — |
| CVE-2026-22627 | HIGH 8.8 | fortinet fortiswitchaxfixed A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the dev | 0.3% | — |
| CVE-2026-21537 | HIGH 8.8 | microsoft defender_for_endpoint Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-21518 | HIGH 8.8 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 1.4% | — |
| CVE-2026-21516 | HIGH 8.8 | microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-21513 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | 15.4% | |
| CVE-2026-21510 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 25.8% | |
| CVE-2026-21262 | HIGH 8.8 | microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 2.0% | — |
| CVE-2026-21256 | HIGH 8.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-21255 | HIGH 8.8 | microsoft windows_10_1607 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-20967 | HIGH 8.8 | microsoft system_center_operations_manager Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2026-20947 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 18.6% | — |
| CVE-2026-20868 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2026-20200 | HIGH 8.8 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. | 5.2% | — |
| CVE-2026-20150 | HIGH 8.8 | cisco roomos As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally d | 0.4% | — |
| CVE-2026-20126 | HIGH 8.8 | cisco catalyst_sd-wan_manager A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the R | 0.3% | — |
| CVE-2026-20098 | HIGH 8.8 | cisco meeting_management A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability i | 0.4% | — |
| CVE-2026-20094 | HIGH 8.8 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulne | 1.1% | — |