58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-87621 | CRIT 9.6 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-76439 | MED 5.3 | A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerabi | 0.3% | — |
| CVE-2026-66314 | MED 6.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-59282 | HIGH 7.5 | vmware spring_framework Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring | 0.3% | — |
| CVE-2026-59271 | MED 5.3 | vmware spring_advanced_message_queuing_protocol When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | 0.3% | — |
| CVE-2026-47894 | MED 4.9 | vmware spring_cloud_config Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config | 0.3% | — |
| CVE-2026-47888 | HIGH 7.5 | vmware spring_framework A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framewor | 0.3% | — |
| CVE-2026-47886 | HIGH 7.5 | vmware spring_framework Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framewor | 0.3% | — |
| CVE-2026-45476 | HIGH 8.2 | microsoft azure_network_adapter Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-4440 | HIGH 8.8 | google chrome Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-40629 | HIGH 7.5 | f5 big-ip_access_policy_manager When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-40618 | HIGH 7.5 | f5 big-ip_access_policy_manager When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the | 0.3% | — |
| CVE-2026-40067 | HIGH 7.5 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-40060 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-19163 | HIGH 8.3 | google chrome Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-19148 | HIGH 8.3 | google chrome Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-19147 | HIGH 8.3 | google chrome Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-15777 | HIGH 7.5 | google chrome Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-15122 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve | 0.3% | — |
| CVE-2026-13829 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sev | 0.3% | — |
| CVE-2026-10971 | CRIT 9.6 | google chrome Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sev | 0.3% | — |
| CVE-2025-49699 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2025-39894 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to | 0.3% | — |
| CVE-2024-45627 | MED 5.9 | apache linkis In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, the par | 0.3% | — |
| CVE-2024-43872 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup under heavy CEQE load CEQEs are handled in interrupt handler currently. This may cause the CPU core staying in interrupt context too long and lead to soft lockup un | 0.3% | — |