IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.793 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-23226 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksm 0.4%
CVE-2026-2321 HIGH 8.8 google chrome Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0.2%
CVE-2026-23193 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In iscsit_dec_session_usage_count(), the function calls complete() while holding the sess->session_usage_lock. Sim 0.2%
CVE-2026-2315 HIGH 8.8 google chrome Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 8.3%
CVE-2026-2314 HIGH 8.8 google chrome Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 4.2%
CVE-2026-2313 HIGH 8.8 google chrome Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 4.1%
CVE-2026-23098 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately freed without checking if nr_neigh->ax25 pointer is NULL. Therefore, if nr_neigh->ax25 is NULL, the ca 0.2%
CVE-2026-22730 HIGH 8.8 vmware spring_ai A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. 0.5%
CVE-2026-22627 HIGH 8.8 fortinet fortiswitchaxfixed A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the dev 0.3%
CVE-2026-21537 HIGH 8.8 microsoft defender_for_endpoint Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. 0.5%
CVE-2026-21518 HIGH 8.8 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 1.4%
CVE-2026-21516 HIGH 8.8 microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-21513 HIGH 8.8 microsoft windows_10_1607 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. 15.4%
CVE-2026-21510 HIGH 8.8 microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. 25.8%
CVE-2026-21262 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 2.0%
CVE-2026-21256 HIGH 8.8 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. 1.1%
CVE-2026-21255 HIGH 8.8 microsoft windows_10_1607 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-20967 HIGH 8.8 microsoft system_center_operations_manager Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2026-20947 HIGH 8.8 microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 18.6%
CVE-2026-20868 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.4%
CVE-2026-20200 HIGH 8.8 cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  5.2%
CVE-2026-20150 HIGH 8.8 cisco roomos As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally d 0.4%
CVE-2026-20126 HIGH 8.8 cisco catalyst_sd-wan_manager A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the R 0.3%
CVE-2026-20098 HIGH 8.8 cisco meeting_management A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability i 0.4%
CVE-2026-20094 HIGH 8.8 cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulne 1.1%