58.211 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.211 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-67589 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes | 0.5% | — |
| CVE-2026-67588 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the | 0.5% | — |
| CVE-2026-67552 | HIGH 7.5 | apache qpid_proton-dotnet A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the i | 0.5% | — |
| CVE-2026-67551 | HIGH 7.5 | apache qpid_proton-dotnet pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fi | 0.5% | — |
| CVE-2026-67465 | HIGH 7.5 | apache qpid_proton-dotnet A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes | 0.5% | — |
| CVE-2026-67376 | HIGH 7.5 | microsoft sql_server_2017 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-67211 | HIGH 7.5 | apache opennlp OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected code.) Des | 0.3% | — |
| CVE-2026-66908 | HIGH 7.5 | apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe | 0.4% | — |
| CVE-2026-66907 | HIGH 7.5 | apache camel Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud Stor | 0.6% | — |
| CVE-2026-66755 | HIGH 7.5 | apache tika Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible | 0.4% | — |
| CVE-2026-66315 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.3% | — |
| CVE-2026-66307 | HIGH 7.5 | microsoft skype_for_business_server Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-66304 | HIGH 7.5 | microsoft skype_for_business_server Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-66274 | HIGH 7.5 | apache qpid_proton-j A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the iss | 0.5% | — |
| CVE-2026-66273 | HIGH 7.5 | apache qpid_proton-j A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fix | 0.4% | — |
| CVE-2026-66257 | HIGH 7.5 | apache qpid_proton-j A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes th | 0.4% | — |
| CVE-2026-66144 | HIGH 7.5 | apache neethi Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes th | 0.5% | — |
| CVE-2026-66143 | HIGH 7.5 | apache neethi It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to ve | 0.5% | — |
| CVE-2026-66142 | HIGH 7.5 | apache neethi Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upg | 0.5% | — |
| CVE-2026-65942 | HIGH 7.5 | apache ranger TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.3% | — |
| CVE-2026-65927 | HIGH 7.5 | apache tomcat Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1. | 0.8% | — |
| CVE-2026-65681 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-65432 | HIGH 7.5 | apache cxf Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declara | 0.4% | — |
| CVE-2026-65324 | HIGH 7.5 | apache traffic_server Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 1 | 0.5% | — |
| CVE-2026-65097 | HIGH 7.5 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informa | 0.2% | — |