56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-9110 | MED 4.2 | google chrome Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical) | 0.3% | — |
| CVE-2026-9103 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication whe | 0.4% | — |
| CVE-2026-9071 | HIGH 7.5 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to c | 0.5% | — |
| CVE-2026-9006 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure | 0.2% | — |
| CVE-2026-8992 | HIGH 8.8 | ivanti secure_access_client An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | 0.6% | — |
| CVE-2026-8859 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl | 0.4% | — |
| CVE-2026-8856 | HIGH 7.7 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration. | 0.2% | — |
| CVE-2026-8855 | HIGH 8.1 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). | 0.5% | — |
| CVE-2026-8854 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | 0.4% | — |
| CVE-2026-8852 | MED 6.2 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. | 0.2% | — |
| CVE-2026-8850 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. | 0.4% | — |
| CVE-2026-8835 | HIGH 7.3 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service. | 0.3% | — |
| CVE-2026-8834 | HIGH 8.0 | ibm http_server IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service. | 0.3% | — |
| CVE-2026-8711 | HIGH 8.1 | f5 njs NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauth | 0.9% | — |
| CVE-2026-8673 | MED 5.9 | avantra avantra Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0. | 0.2% | — |
| CVE-2026-8672 | MED 5.1 | avantra avantra Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0. | 0.1% | — |
| CVE-2026-8671 | HIGH 7.5 | avantra avantra Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. | 0.2% | — |
| CVE-2026-8670 | CRIT 9.6 | avantra avantra Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1. | 0.2% | — |
| CVE-2026-8666 | HIGH 7.7 | rapid7 insightconnect_traceroute OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient inpu | 0.7% | — |
| CVE-2026-8665 | HIGH 7.7 | rapid7 insightconnect_translate OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command constr | 0.7% | — |
| CVE-2026-8663 | MED 6.0 | rapid7 insightconnect_rpm OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction. | 0.8% | — |
| CVE-2026-8662 | LOW 3.3 | rapid7 insightconnect_compression Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content ca | 0.2% | — |
| CVE-2026-8660 | HIGH 7.7 | rapid7 insightconnect_ping OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. | 0.7% | — |
| CVE-2026-8659 | MED 6.0 | rapid7 insightconnect_sqlmap OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation. | 0.8% | — |
| CVE-2026-8658 | MED 6.0 | rapid7 insightconnect_tcpdump OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. | 0.8% | — |