56.966 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.966 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-5288 | CRIT 9.6 | google chrome Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-50380 | CRIT 9.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-48582 | CRIT 9.6 | microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-48561 | CRIT 9.6 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-48317 | CRIT 9.6 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker coul | 0.5% | — |
| CVE-2026-47281 | CRIT 9.6 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-42904 | CRIT 9.6 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2026-41615 | CRIT 9.6 | microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-3916 | CRIT 9.6 | google chrome Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3545 | CRIT 9.6 | google chrome Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-35428 | CRIT 9.6 | microsoft azure_cloud_shell Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-33823 | CRIT 9.6 | microsoft teams Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-28373 | CRIT 9.6 | stackfield stackfield The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesys | 0.4% | — |
| CVE-2026-27303 | CRIT 9.6 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 0.6% | — |
| CVE-2026-26135 | CRIT 9.6 | microsoft azure_custom_locations_resource_provider Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-24303 | CRIT 9.6 | microsoft partner_center Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-19171 | CRIT 9.6 | google chrome Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-19149 | CRIT 9.6 | google chrome Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-18972 | CRIT 9.6 | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. | 6.1% | — |
| CVE-2026-17692 | CRIT 9.6 | google chrome Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-17691 | CRIT 9.6 | google chrome Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-15773 | CRIT 9.6 | google chrome Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-14113 | CRIT 9.6 | google chrome Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-14095 | CRIT 9.6 | google chrome Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-14093 | CRIT 9.6 | google chrome Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |