IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.580 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-58154 HIGH 8.9 apache traffic_server Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad 0.4%
CVE-2026-58153 HIGH 8.3 apache traffic_server Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 0.5%
CVE-2026-58152 MED 5.9 apache traffic_server Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to ve 0.3%
CVE-2026-58151 HIGH 7.5 apache traffic_server Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended 0.5%
CVE-2026-58150 CRIT 10.0 apache traffic_server Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended 0.3%
CVE-2026-58076 HIGH 8.8 apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's 0.5%
CVE-2026-58065 HIGH 8.1 apache apache-airflow-providers-git The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the se 0.5%
CVE-2026-58023 CRIT 9.1 apache thrift Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 1.1%
CVE-2026-57993 HIGH 7.4 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-57992 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57991 HIGH 7.4 microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-57990 HIGH 7.4 microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-57989 HIGH 7.4 microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.4%
CVE-2026-57988 HIGH 7.1 microsoft edge_chromium Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-57987 MED 6.5 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-57986 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-57985 HIGH 7.6 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-57984 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-57983 HIGH 8.7 microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.5%
CVE-2026-57982 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-57981 HIGH 8.8 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57980 MED 5.4 microsoft edge_chromium Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. 0.2%
CVE-2026-57979 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-57978 MED 5.4 microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.2%
CVE-2026-57977 HIGH 7.1 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%