IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.705 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-41707 HIGH 7.4 Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing a 0.3%
CVE-2026-41706 MED 6.1 vmware spring_security Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute 0.2%
CVE-2026-41705 HIGH 8.6 vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 0.4%
CVE-2026-41702 HIGH 7.8 vmware fusion VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to roo 0.1%
CVE-2026-41700 HIGH 8.1 vmware spring_for_graphql Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operation 0.2%
CVE-2026-41699 HIGH 8.1 vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) f 0.4%
CVE-2026-41696 MED 5.9 vmware spring_data_mongodb Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affect 0.3%
CVE-2026-41694 LOW 3.7 vmware spring_security Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affe 0.1%
CVE-2026-41636 HIGH 7.5 apache thrift Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.5%
CVE-2026-41635 CRIT 9.8 apache mina Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the cl 0.6%
CVE-2026-41615 CRIT 9.6 microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-41614 MED 6.2 microsoft 365_copilot Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. 0.4%
CVE-2026-41613 HIGH 8.8 microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-41612 MED 5.5 microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-41611 HIGH 7.8 microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-41610 MED 6.3 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.6%
CVE-2026-41608 HIGH 7.5 apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.6%
CVE-2026-41607 MED 6.5 apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.9%
CVE-2026-41606 MED 5.3 apache thrift Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 1.1%
CVE-2026-41605 HIGH 7.3 apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.9%
CVE-2026-41604 HIGH 8.2 apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.9%
CVE-2026-41602 HIGH 7.5 apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 1.2%
CVE-2026-41409 CRIT 9.8 apache mina The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Aff 0.4%
CVE-2026-41293 CRIT 9.8 apache tomcat Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also 1.6%
CVE-2026-41284 HIGH 7.5 apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affec 0.8%