58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-67369 | MED 6.5 | microsoft sql_server_2025 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-66816 | MED 6.5 | microsoft sql_server_2022 Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2026-66391 | MED 6.5 | apache wicket Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the is | 0.4% | — |
| CVE-2026-66326 | MED 6.5 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-66324 | MED 6.5 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-66314 | MED 6.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-66308 | MED 6.5 | microsoft skype_for_business_server Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-66306 | MED 6.5 | microsoft skype_for_business_server Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-66303 | MED 6.5 | microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-66301 | MED 6.5 | microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-66277 | MED 6.5 | apache qpid_proton-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users ar | 0.4% | — |
| CVE-2026-66276 | MED 6.5 | apache qpid_proton-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgr | 0.4% | — |
| CVE-2026-66275 | MED 6.5 | apache qpid_proton-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | 0.4% | — |
| CVE-2026-65945 | MED 6.5 | apache ranger Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.4% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-65806 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-65794 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-65785 | MED 6.5 | microsoft windows_11_24h2 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | 0.4% | — |
| CVE-2026-65769 | MED 6.5 | microsoft teams Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-65017 | MED 6.5 | apache airflow Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with n | 0.4% | — |
| CVE-2026-64918 | MED 6.5 | microsoft 365_apps Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-64640 | MED 6.5 | apache polaris Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to | 0.4% | — |
| CVE-2026-63523 | MED 6.5 | microsoft skype_for_business_server Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-63516 | MED 6.5 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.3% | — |