58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-6052 | MED 6.5 | ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables. | 0.4% | — |
| CVE-2026-59320 | MED 6.5 | vmware spring_advanced_message_queuing_protocol When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and | 0.4% | — |
| CVE-2026-59318 | MED 6.5 | vmware spring_ai In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invok | 0.3% | — |
| CVE-2026-59317 | MED 6.5 | vmware spring_for_apache_kafka DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring fo | 0.4% | — |
| CVE-2026-59278 | MED 6.5 | vmware spring_for_apache_kafka JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.Ine | 0.3% | — |
| CVE-2026-59274 | MED 6.5 | vmware spring_integration The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integrat | 0.4% | — |
| CVE-2026-59244 | MED 6.5 | apache airflow Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` wa | 0.4% | — |
| CVE-2026-59230 | MED 6.5 | apache camel Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-mail component ships a MimeMultipart data format that can unmarshal a MIM | 0.7% | — |
| CVE-2026-5919 | MED 6.5 | google chrome Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-59138 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-5905 | MED 6.5 | google chrome Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-5903 | MED 6.5 | google chrome Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | 0.3% | — |
| CVE-2026-5901 | MED 6.5 | google chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromi | 0.2% | — |
| CVE-2026-5888 | MED 6.5 | google chrome Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5885 | MED 6.5 | google chrome Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5881 | MED 6.5 | google chrome Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-5876 | MED 6.5 | google chrome Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | 0.3% | — |
| CVE-2026-58639 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-58546 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-58539 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-58535 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-58533 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-58523 | MED 6.5 | microsoft edge_chromium Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2026-58301 | MED 6.5 | apache shiro When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Ap | 0.5% | — |
| CVE-2026-58279 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |