IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-59318 MED 6.5 vmware spring_ai In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invok 0.3% —
CVE-2026-59317 MED 6.5 vmware spring_for_apache_kafka DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring fo 0.4% —
CVE-2026-59278 MED 6.5 vmware spring_for_apache_kafka JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.Ine 0.3% —
CVE-2026-59274 MED 6.5 vmware spring_integration The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integrat 0.4% —
CVE-2026-59244 MED 6.5 apache airflow Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` wa 0.2% —
CVE-2026-59230 MED 6.5 apache camel Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-mail component ships a MimeMultipart data format that can unmarshal a MIM 0.4% —
CVE-2026-5919 MED 6.5 google chrome Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low) 0.2% —
CVE-2026-59138 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. 1.0% —
CVE-2026-5905 MED 6.5 google chrome Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) 0.2% —
CVE-2026-5903 MED 6.5 google chrome Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) 0.3% —
CVE-2026-5901 MED 6.5 google chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromi 0.1% —
CVE-2026-5888 MED 6.5 google chrome Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) 0.3% —
CVE-2026-5885 MED 6.5 google chrome Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2026-5881 MED 6.5 google chrome Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2026-5876 MED 6.5 google chrome Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0.2% —
CVE-2026-58639 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.8% —
CVE-2026-58546 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-58539 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-58535 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-58533 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9% —
CVE-2026-58523 MED 6.5 microsoft edge_chromium Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. 0.9% —
CVE-2026-58301 MED 6.5 apache shiro When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Ap 0.5% —
CVE-2026-58279 MED 6.5 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.6% —
CVE-2026-58160 MED 6.5 apache traffic_server Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, whic 0.4% —
CVE-2026-57987 MED 6.5 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.9% —