IT
57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.918 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-64286 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest co 0.2%
CVE-2026-60005 HIGH 8.2 f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause 0.7%
CVE-2026-5944 HIGH 8.2 cisco intersight_device_connector An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment witho 0.5%
CVE-2026-59324 HIGH 8.2 vmware spring_integration When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propaga 0.2%
CVE-2026-58525 HIGH 8.2 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-58188 HIGH 8.2 apache traffic_server Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to vers 0.4%
CVE-2026-58184 HIGH 8.2 apache traffic_server The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users 0.3%
CVE-2026-58159 HIGH 8.2 apache traffic_server Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade 0.3%
CVE-2026-57239 HIGH 8.2 foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. 0.2%
CVE-2026-53268 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This h 0.4%
CVE-2026-50680 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50528 HIGH 8.2 microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.6%
CVE-2026-50429 HIGH 8.2 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2026-50338 HIGH 8.2 microsoft azure_spring_cloud Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-48345 HIGH 8.2 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0.9%
CVE-2026-48290 HIGH 8.2 adobe c2pa CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page 0.3%
CVE-2026-47877 HIGH 8.2 vmware spring_security Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 0.2%
CVE-2026-47652 HIGH 8.2 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 0.3%
CVE-2026-47623 HIGH 8.2 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. 0.4%
CVE-2026-46591 HIGH 8.2 apache camel Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-202 0.5%
CVE-2026-46303 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checkin 0.3%
CVE-2026-46037 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[] 0.4%
CVE-2026-45843 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith 0.4%
CVE-2026-45476 HIGH 8.2 microsoft azure_network_adapter Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44822 HIGH 8.2 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.5%