57.139 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.139 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-5279 | HIGH 8.8 | google chrome Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-5278 | HIGH 8.8 | google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-5275 | HIGH 8.8 | google chrome Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-5274 | HIGH 8.8 | google chrome Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-5272 | HIGH 8.8 | google chrome Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-50692 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50687 | HIGH 8.8 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50670 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50666 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-50663 | HIGH 8.8 | microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-50622 | HIGH 8.8 | apache atlas Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue a | 0.3% | — |
| CVE-2026-50489 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50477 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50474 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50444 | HIGH 8.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50438 | HIGH 8.8 | microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-50413 | HIGH 8.8 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50398 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50385 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50382 | HIGH 8.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-50370 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-50369 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-50360 | HIGH 8.8 | microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50342 | HIGH 8.8 | microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50223 | HIGH 8.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi | 0.7% | — |