58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-9006 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure | 0.4% | — |
| CVE-2026-8646 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowi | 0.6% | — |
| CVE-2026-84003 | HIGH 7.4 | microsoft azure\/msal-node Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-81383 | HIGH 7.4 | microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-78461 | HIGH 7.4 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2026-78254 | HIGH 7.4 | apache ant The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker' | 0.5% | — |
| CVE-2026-66321 | HIGH 7.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-65802 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-59288 | HIGH 7.4 | vmware spring_for_graphql The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2 | 0.3% | — |
| CVE-2026-58612 | HIGH 7.4 | microsoft powershell Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-57993 | HIGH 7.4 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-57991 | HIGH 7.4 | microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-57990 | HIGH 7.4 | microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-57989 | HIGH 7.4 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-54127 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-53561 | HIGH 7.4 | apache hive An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network | 0.3% | — |
| CVE-2026-50631 | HIGH 7.4 | apache cxf A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed | 0.3% | — |
| CVE-2026-48287 | HIGH 7.4 | adobe c2pa CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires use | 0.2% | — |
| CVE-2026-47841 | HIGH 7.4 | vmware spring_security An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 | 0.3% | — |
| CVE-2026-46320 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the | 0.2% | — |
| CVE-2026-42893 | HIGH 7.4 | microsoft outlook Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. | 0.4% | — |
| CVE-2026-41707 | HIGH 7.4 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing a | 0.3% | — |
| CVE-2026-41107 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-40414 | HIGH 7.4 | microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability | 0.5% | — |
| CVE-2026-40413 | HIGH 7.4 | microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability | 0.4% | — |