IT
57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.921 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-1999-0468 HIGH 8.2 microsoft internet_explorer Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. 3.2%
CVE-2026-9256 HIGH 8.1 debian debian_linux NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/( 10.9%
CVE-2026-8855 HIGH 8.1 ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). 0.5%
CVE-2026-87554 HIGH 8.1 google chrome Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) 0.1%
CVE-2026-87530 HIGH 8.1 google chrome Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) 0.2%
CVE-2026-87509 HIGH 8.1 google chrome Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low) 0.2%
CVE-2026-87467 HIGH 8.1 google chrome Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) 0.1%
CVE-2026-87457 HIGH 8.1 google chrome Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) 0.1%
CVE-2026-8711 HIGH 8.1 f5 njs NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauth 9.7%
CVE-2026-86466 HIGH 8.1 Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client applic 0.1%
CVE-2026-84334 HIGH 8.1 google chrome Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) 0.1%
CVE-2026-83997 HIGH 8.1 microsoft windows_10_21h2 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-82438 HIGH 8.1 Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while 0.2%
CVE-2026-82432 HIGH 8.1 Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller author 0.3%
CVE-2026-80354 HIGH 8.1 apache camel Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to 0.2%
CVE-2026-8018 HIGH 8.1 google chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low) 0.3%
CVE-2026-7981 HIGH 8.1 google chrome Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) 0.2%
CVE-2026-79194 HIGH 8.1 google chrome Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) 0.5%
CVE-2026-78689 HIGH 8.1 Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an extern 0.5%
CVE-2026-78450 HIGH 8.1 microsoft windows_10_1809 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-78444 HIGH 8.1 microsoft windows_10_1809 Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-75020 HIGH 8.1 apache apisix Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different e 0.5%
CVE-2026-7347 HIGH 8.1 google chrome Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) 0.5%
CVE-2026-7346 HIGH 8.1 google chrome Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-73334 HIGH 8.1 apache parquet Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Manageme 0.2%