57.139 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-64093 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming i | 0.3% | — |
| CVE-2026-64088 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_orig_node::tt_buff_len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assig | 0.3% | — |
| CVE-2026-6406 | HIGH 8.8 | docker docker_desktop The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the - | 0.2% | — |
| CVE-2026-63807 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level When recovering hugepages in the shadow MMU, verify that the base gfn of the shadow page is actually contained w | 0.1% | — |
| CVE-2026-63801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to crypto_aead_decrypt(req) without taking a reference on the netns, u | 0.5% | — |
| CVE-2026-63796 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors ocfs2_validate_gd_parent() only bounds bg_bits against the parent allocator's chain geometry. A malicious descriptor can still claim a bg_si | 0.5% | — |
| CVE-2026-63514 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.5% | — |
| CVE-2026-6318 | HIGH 8.8 | google chrome Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-6317 | HIGH 8.8 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6316 | HIGH 8.8 | google chrome Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-63093 | HIGH 8.8 | anysphere cursor Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted reposi | 0.6% | — |
| CVE-2026-6307 | HIGH 8.8 | google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-6306 | HIGH 8.8 | google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6305 | HIGH 8.8 | google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-63046 | HIGH 8.8 | apache inlong Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issu | 0.4% | — |
| CVE-2026-63041 | HIGH 8.8 | apache apisix Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitis | 0.7% | — |
| CVE-2026-6303 | HIGH 8.8 | google chrome Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-6302 | HIGH 8.8 | google chrome Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6301 | HIGH 8.8 | google chrome Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-6300 | HIGH 8.8 | google chrome Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-6299 | HIGH 8.8 | google chrome Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-62913 | HIGH 8.8 | microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62872 | HIGH 8.8 | microsoft .net_framework Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-62870 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62869 | HIGH 8.8 | microsoft entra_id Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | 0.8% | — |