58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-68868 | MED 6.5 | apache apache-airflow-providers-google The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every | 0.5% | — |
| CVE-2026-68784 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68781 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68780 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68779 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-68778 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68777 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68776 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-68080 | MED 6.5 | apache qpid_broker-j It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are | 0.4% | — |
| CVE-2026-68078 | MED 6.5 | apache qpid_broker-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users ar | 0.4% | — |
| CVE-2026-68077 | MED 6.5 | apache qpid_broker-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgr | 0.4% | — |
| CVE-2026-68075 | MED 6.5 | apache qpid_broker-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. | 0.4% | — |
| CVE-2026-67648 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-67645 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-67641 | MED 6.5 | microsoft sql_server_2022 Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-67633 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-67591 | MED 6.5 | apache qpid_protonj2 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | 0.4% | — |
| CVE-2026-67555 | MED 6.5 | apache qpid_proton-dotnet It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users | 0.4% | — |
| CVE-2026-67554 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to | 0.4% | — |
| CVE-2026-67553 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | 0.4% | — |
| CVE-2026-67393 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-67390 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-67389 | MED 6.5 | microsoft sql_server_2022 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-67386 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-67383 | MED 6.5 | microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |