56.727 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.727 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-66755 | HIGH 7.5 | apache tika Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible | 0.4% | — |
| CVE-2026-66722 | HIGH 7.2 | apache cloudstack Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just th | 0.3% | — |
| CVE-2026-66721 | LOW 2.7 | apache cloudstack Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. | 0.2% | — |
| CVE-2026-66713 | CRIT 9.8 | apache axis2\/java Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthentic | 1.0% | — |
| CVE-2026-66422 | HIGH 8.1 | apache tomcat Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0. | 0.4% | — |
| CVE-2026-66391 | MED 6.5 | apache wicket Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the is | 0.4% | — |
| CVE-2026-66390 | MED 6.1 | apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, | 0.4% | — |
| CVE-2026-66326 | MED 6.5 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-66325 | MED 6.1 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-66324 | MED 6.5 | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | — | — |
| CVE-2026-66323 | MED 5.4 | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.3% | — |
| CVE-2026-66322 | HIGH 7.1 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-66321 | HIGH 7.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-66318 | HIGH 8.1 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.2% | — |
| CVE-2026-66317 | MED 5.4 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | 0.1% | — |
| CVE-2026-66316 | MED 5.4 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.1% | — |
| CVE-2026-66315 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.3% | — |
| CVE-2026-66314 | MED 6.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-66313 | MED 6.8 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | 0.2% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-66311 | MED 6.2 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | 0.3% | — |
| CVE-2026-66310 | HIGH 7.7 | microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | 0.2% | — |
| CVE-2026-66309 | CRIT 9.1 | microsoft azure_sql_database Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-66301 | MED 6.5 | microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-66299 | MED 5.3 | apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guida | 0.5% | — |