58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-76646 | HIGH 7.5 | A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recommended to upgrade to vers | 0.5% | — |
| CVE-2026-76442 | HIGH 7.5 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.4% | — |
| CVE-2026-75005 | HIGH 7.5 | apache apisix Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upg | 0.8% | — |
| CVE-2026-74848 | HIGH 7.5 | apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache | 0.6% | — |
| CVE-2026-74761 | HIGH 7.5 | apache activemq Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Brok | 0.4% | — |
| CVE-2026-73635 | HIGH 7.5 | apache struts Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the frame | 0.5% | — |
| CVE-2026-73634 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request | 0.4% | — |
| CVE-2026-73633 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single re | 0.6% | — |
| CVE-2026-7357 | HIGH 7.5 | google chrome Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7349 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-7343 | HIGH 7.5 | google chrome Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-7338 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-73017 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | 0.2% | — |
| CVE-2026-72989 | HIGH 7.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-72954 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-72949 | HIGH 7.5 | microsoft windows_11_23h2 Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-72943 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-72932 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-72928 | HIGH 7.5 | microsoft windows_server_2025 Use after free in Windows DNS allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-71559 | HIGH 7.5 | apache fory Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache F | 0.4% | — |
| CVE-2026-71330 | HIGH 7.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-71257 | HIGH 7.5 | apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f | 0.7% | — |
| CVE-2026-70587 | HIGH 7.5 | microsoft windows_10_1607 Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-70579 | HIGH 7.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-70570 | HIGH 7.5 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.4% | — |