57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-47389 | MED 5.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: fix missing sev_decommission in sev_receive_start DECOMMISSION the current SEV context if binding an ASID fails after RECEIVE_START. Per AMD's SEV API, RECEIVE_START generates a n | 0.2% | — |
| CVE-2021-41028 | HIGH 8.2 | fortinet forticlient A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 an | 0.2% | — |
| CVE-2026-9975 | HIGH 8.3 | google chrome Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9970 | HIGH 8.3 | google chrome Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9966 | HIGH 8.3 | google chrome Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9954 | HIGH 7.5 | google chrome Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9905 | HIGH 8.3 | google chrome Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-9890 | HIGH 8.3 | google chrome Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-8510 | HIGH 7.5 | google chrome Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-66053 | MED 5.9 | apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603 | 0.2% | — |
| CVE-2026-65779 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65778 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65678 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62777 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58527 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-58526 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-54991 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-54107 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50676 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50673 | HIGH 7.8 | microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50667 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50440 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50378 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50321 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50317 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | 0.2% | — |