57.139 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62827 | HIGH 8.8 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-62824 | HIGH 8.8 | microsoft windows_10_1607 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62823 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2026-62822 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62818 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-62817 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2026-62816 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | 0.4% | — |
| CVE-2026-62800 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-62795 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62790 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62785 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-62784 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-61400 | HIGH 8.8 | apache cloudstack Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions required to in | 1.5% | — |
| CVE-2026-59799 | HIGH 8.8 | apache cloudstack Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4 | 0.3% | — |
| CVE-2026-5914 | HIGH 8.8 | google chrome Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-59133 | HIGH 8.8 | microsoft windows_app Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-5912 | HIGH 8.8 | google chrome Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-5910 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-5909 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-5908 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-5884 | HIGH 8.8 | google chrome Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medi | 0.3% | — |
| CVE-2026-5883 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5877 | HIGH 8.8 | google chrome Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5873 | HIGH 8.8 | google chrome Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |