IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.580 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-57976 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 0.8%
CVE-2026-57975 HIGH 7.5 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-57974 HIGH 8.8 microsoft edge_chromium Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57973 MED 6.3 microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-57969 HIGH 8.8 microsoft azure_cyclecloud Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-57968 HIGH 7.8 microsoft windows_subsystem_for_linux Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-57834 CRIT 10.0 apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 0.3%
CVE-2026-57821 HIGH 8.1 apache fineract A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated us 0.8%
CVE-2026-57819 HIGH 7.5 apache cxf Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large n 0.5%
CVE-2026-57818 HIGH 8.1 apache cxf A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 0.3%
CVE-2026-57817 HIGH 8.1 apache cxf The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the 0.4%
CVE-2026-57308 CRIT 9.8 apache syncope Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameter 0.5%
CVE-2026-57260 HIGH 7.8 foxit pdf_editor The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash. 0.2%
CVE-2026-57259 MED 6.5 foxit pdf_editor The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, thro 0.2%
CVE-2026-57258 MED 6.1 foxit pdf_editor The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes. 0.1%
CVE-2026-57257 MED 6.1 foxit pdf_editor During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes. 0.1%
CVE-2026-57256 HIGH 7.8 foxit pdf_editor When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form o 0.1%
CVE-2026-57255 MED 6.1 foxit pdf_editor The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds 0.1%
CVE-2026-57254 HIGH 7.8 foxit pdf_editor There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash. 0.1%
CVE-2026-57253 MED 6.1 foxit pdf_editor An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing. 0.1%
CVE-2026-57252 HIGH 7.8 foxit pdf_editor When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing. 0.1%
CVE-2026-57251 HIGH 7.8 foxit pdf_editor The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper limit and consistency checks. Out-of-bounds access to the underlying array is exposed, ultimately leading to a crash of the application. 0.1%
CVE-2026-57250 HIGH 7.8 foxit pdf_editor When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the applicati 0.1%
CVE-2026-57249 HIGH 7.8 foxit pdf_editor After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the re-entry process, the application access invalid objects and crashed. 0.1%
CVE-2026-57248 HIGH 7.8 foxit pdf_editor When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash du 0.1%