IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50645 HIGH 7.5 apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 0.5% —
CVE-2026-50527 HIGH 7.5 microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. 0.8% —
CVE-2026-50525 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.6% —
CVE-2026-50524 HIGH 7.5 microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. 0.6% —
CVE-2026-50506 HIGH 7.5 microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50505 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. 0.7% —
CVE-2026-50500 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-50496 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.2% —
CVE-2026-50470 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-50463 HIGH 7.5 microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.0% —
CVE-2026-50424 HIGH 7.5 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50414 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0.6% —
CVE-2026-50411 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50379 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0.5% —
CVE-2026-50368 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50355 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50330 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. 1.3% —
CVE-2026-50328 HIGH 7.5 microsoft windows_10_1607 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. 1.2% —
CVE-2026-50304 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-50222 HIGH 7.5 apache cloudstack Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserData 0.3% —
CVE-2026-49975 HIGH 7.5 apache http_server Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. 34.3% —
CVE-2026-49788 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-49787 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 1.2% —
CVE-2026-49486 HIGH 7.5 apache apache-airflow-providers-ftp The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTP 0.4% —
CVE-2026-49434 HIGH 7.5 apache activemq Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports i 0.6% —