57.148 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.148 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-3920 | HIGH 8.8 | google chrome Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3919 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3918 | HIGH 8.8 | google chrome Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3917 | HIGH 8.8 | google chrome Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3915 | HIGH 8.8 | google chrome Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2026-3914 | HIGH 8.8 | google chrome Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3913 | HIGH 8.8 | google chrome Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-3910 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 2.0% | |
| CVE-2026-3909 | HIGH 8.8 | google chrome Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 1.6% | |
| CVE-2026-3544 | HIGH 8.8 | google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-35439 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-35436 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-35430 | HIGH 8.8 | microsoft azure_privileged_identity_management Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-3543 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3541 | HIGH 8.8 | google chrome Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3540 | HIGH 8.8 | google chrome Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3538 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-3537 | HIGH 8.8 | google chrome Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.4% | — |
| CVE-2026-3536 | HIGH 8.8 | google chrome Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2026-35337 | HIGH 8.8 | apache storm Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.r | 1.0% | — |
| CVE-2026-35152 | HIGH 8.8 | apache fineract A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authen | 3.3% | — |
| CVE-2026-34329 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-34197 | HIGH 8.8 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia | 98.3% | |
| CVE-2026-33858 | HIGH 8.8 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0.6% | — |