IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-59289 HIGH 7.5 vmware spring_for_graphql Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memor 0.5% —
CVE-2026-59282 HIGH 7.5 vmware spring_framework Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring 0.3% —
CVE-2026-59279 HIGH 7.5 vmware spring_ai The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate 0.5% —
CVE-2026-59173 HIGH 7.5 apache traffic_server Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. 0.7% —
CVE-2026-59134 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-59132 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. 1.7% —
CVE-2026-59117 HIGH 7.5 microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-58627 HIGH 7.5 microsoft windows_10_1607 Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-58531 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-58389 HIGH 7.5 apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.6% —
CVE-2026-58299 HIGH 7.5 microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-58294 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-58292 HIGH 7.5 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5% —
CVE-2026-58290 HIGH 7.5 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4% —
CVE-2026-58276 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6% —
CVE-2026-58189 HIGH 7.5 apache traffic_server Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomme 0.4% —
CVE-2026-58186 HIGH 7.5 apache traffic_server The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to 0.4% —
CVE-2026-58181 HIGH 7.5 apache traffic_server The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to up 0.4% —
CVE-2026-58180 HIGH 7.5 apache traffic_server The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to versio 0.4% —
CVE-2026-58178 HIGH 7.5 apache traffic_server The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to 0.4% —
CVE-2026-58175 HIGH 7.5 apache traffic_server Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, whic 0.4% —
CVE-2026-58164 HIGH 7.5 apache traffic_server Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to 0.4% —
CVE-2026-58163 HIGH 7.5 apache traffic_server Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgr 0.4% —
CVE-2026-58161 HIGH 7.5 apache traffic_server Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad 0.4% —
CVE-2026-58151 HIGH 7.5 apache traffic_server Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended 0.5% —