58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-47886 | HIGH 7.5 | vmware spring_framework Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framewor | 0.3% | — |
| CVE-2026-47885 | HIGH 7.5 | vmware spring_framework The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 | 0.3% | — |
| CVE-2026-47852 | HIGH 7.5 | vmware spring_ai A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 | 0.2% | — |
| CVE-2026-47851 | HIGH 7.5 | vmware spring_ai Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 | 0.3% | — |
| CVE-2026-47827 | HIGH 7.5 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities | 1.2% | — |
| CVE-2026-47654 | HIGH 7.5 | microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-47633 | HIGH 7.5 | microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-47629 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. | 0.4% | — |
| CVE-2026-47628 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | 0.4% | — |
| CVE-2026-47618 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | 0.3% | — |
| CVE-2026-47617 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. | 0.3% | — |
| CVE-2026-47616 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | 0.3% | — |
| CVE-2026-47615 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | 0.3% | — |
| CVE-2026-47614 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | 0.3% | — |
| CVE-2026-47613 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to informa | 0.3% | — |
| CVE-2026-47612 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. | 0.6% | — |
| CVE-2026-47476 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | 0.5% | — |
| CVE-2026-47430 | HIGH 7.5 | apache cordova_inappbrowser ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside t | 0.7% | — |
| CVE-2026-47302 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 1.0% | — |
| CVE-2026-47296 | HIGH 7.5 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-46726 | HIGH 7.5 | apache camel Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket component. The camel-vertx-websocket consumer mapped inbound WebSocket query and path pa | 0.9% | — |
| CVE-2026-46592 | HIGH 7.5 | apache camel Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespa | 0.6% | — |
| CVE-2026-46585 | HIGH 7.5 | apache camel Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain stri | 0.6% | — |
| CVE-2026-46457 | HIGH 7.5 | apache camel Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules | 0.7% | — |
| CVE-2026-46306 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating P | 0.4% | — |