57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.918 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-64286 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest co | 0.2% | — |
| CVE-2026-60005 | HIGH 8.2 | f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause | 0.7% | — |
| CVE-2026-5944 | HIGH 8.2 | cisco intersight_device_connector An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment witho | 0.5% | — |
| CVE-2026-59324 | HIGH 8.2 | vmware spring_integration When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propaga | 0.2% | — |
| CVE-2026-58525 | HIGH 8.2 | microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-58188 | HIGH 8.2 | apache traffic_server Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to vers | 0.4% | — |
| CVE-2026-58184 | HIGH 8.2 | apache traffic_server The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users | 0.3% | — |
| CVE-2026-58159 | HIGH 8.2 | apache traffic_server Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade | 0.3% | — |
| CVE-2026-57239 | HIGH 8.2 | foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. | 0.2% | — |
| CVE-2026-53268 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This h | 0.4% | — |
| CVE-2026-50680 | HIGH 8.2 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50528 | HIGH 8.2 | microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2026-50429 | HIGH 8.2 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2026-50338 | HIGH 8.2 | microsoft azure_spring_cloud Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-48345 | HIGH 8.2 | adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera | 0.9% | — |
| CVE-2026-48290 | HIGH 8.2 | adobe c2pa CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page | 0.3% | — |
| CVE-2026-47877 | HIGH 8.2 | vmware spring_security Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 | 0.2% | — |
| CVE-2026-47652 | HIGH 8.2 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-47623 | HIGH 8.2 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | 0.4% | — |
| CVE-2026-46591 | HIGH 8.2 | apache camel Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-202 | 0.5% | — |
| CVE-2026-46303 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checkin | 0.3% | — |
| CVE-2026-46037 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[] | 0.4% | — |
| CVE-2026-45843 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith | 0.4% | — |
| CVE-2026-45476 | HIGH 8.2 | microsoft azure_network_adapter Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44822 | HIGH 8.2 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.5% | — |