56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-46332 | HIGH 8.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer before parsing bootloader packets. The helper can keep le | 0.2% | — |
| CVE-2026-45644 | HIGH 8.0 | microsoft live_share_canvas Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-42975 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-41724 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.3% | — |
| CVE-2026-41723 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.4% | — |
| CVE-2026-41722 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.3% | — |
| CVE-2026-40400 | HIGH 8.0 | microsoft windows_10_1607 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-40368 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-35425 | HIGH 8.0 | microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-34693 | HIGH 8.0 | adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevat | 0.3% | — |
| CVE-2026-34332 | HIGH 8.0 | microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-33826 | HIGH 8.0 | microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-32172 | HIGH 8.0 | microsoft power_apps Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. | 0.3% | — |
| CVE-2026-27912 | HIGH 8.0 | microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2026-26111 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-25173 | HIGH 8.0 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-25172 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-22720 | HIGH 8.0 | vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, | 0.4% | — |
| CVE-2026-21523 | HIGH 8.0 | microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-21257 | HIGH 8.0 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-21229 | HIGH 8.0 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-20960 | HIGH 8.0 | microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-20931 | HIGH 8.0 | microsoft windows_10_1607 External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | 0.8% | — |
| CVE-2026-20155 | HIGH 8.0 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnera | 0.3% | — |
| CVE-2026-11241 | HIGH 8.0 | google chrome Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) | 0.1% | — |