58.202 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.202 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-77898 | HIGH 7.5 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-77895 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-77893 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-77890 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-77889 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-77888 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-77886 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-77502 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-77501 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-77499 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-77498 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-77494 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-77104 | HIGH 7.5 | commvault commvault CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.4% | — |
| CVE-2026-77103 | HIGH 7.5 | commvault commvault CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.3% | — |
| CVE-2026-77102 | HIGH 7.5 | commvault commvault CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.3% | — |
| CVE-2026-77101 | HIGH 7.5 | commvault commvault CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | 0.3% | — |
| CVE-2026-76646 | HIGH 7.5 | A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recommended to upgrade to vers | 0.5% | — |
| CVE-2026-76442 | HIGH 7.5 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software har | 0.4% | — |
| CVE-2026-75005 | HIGH 7.5 | apache apisix Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upg | 0.8% | — |
| CVE-2026-74848 | HIGH 7.5 | apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache | 0.6% | — |
| CVE-2026-74761 | HIGH 7.5 | apache activemq Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Brok | 0.4% | — |
| CVE-2026-73635 | HIGH 7.5 | apache struts Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the frame | 0.5% | — |
| CVE-2026-73634 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request | 0.4% | — |
| CVE-2026-73633 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single re | 0.6% | — |
| CVE-2026-7357 | HIGH 7.5 | google chrome Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |