IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-9153 MED 6.5 gnu sed Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation. 0.5% —
CVE-2026-9138 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input 0.4% —
CVE-2026-87454 MED 6.5 google chrome Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) 0.3% —
CVE-2026-86465 MED 6.5 apache apache-airflow-providers-akeyless Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the back 0.8% —
CVE-2026-8550 MED 6.5 google chrome Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High 0.2% —
CVE-2026-82561 MED 6.5 apache nifi Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework 0.3% —
CVE-2026-82434 MED 6.5 Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only 0.5% —
CVE-2026-82433 MED 6.5 Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and trustst 0.4% —
CVE-2026-82426 MED 6.5 Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that 0.5% —
CVE-2026-81381 MED 6.5 microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.6% —
CVE-2026-81377 MED 6.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0.8% —
CVE-2026-80091 MED 6.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.7% —
CVE-2026-80090 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80089 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80088 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80087 MED 6.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.7% —
CVE-2026-80086 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.7% —
CVE-2026-80084 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. 0.7% —
CVE-2026-80082 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.7% —
CVE-2026-80079 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80078 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80076 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-80073 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-7982 MED 6.5 google chrome Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2026-79285 MED 6.5 google chrome Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0.3% —