IT
57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.436 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-73237 MED 6.1 apache allura XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. 0.4%
CVE-2026-66390 MED 6.1 apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, 0.4%
CVE-2026-66325 MED 6.1 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.2%
CVE-2026-65804 MED 6.1 microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.2%
CVE-2026-59281 MED 6.1 vmware spring_framework Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript 0.2%
CVE-2026-5899 MED 6.1 google chrome Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium securit 0.1%
CVE-2026-5896 MED 6.1 google chrome Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low) 0.2%
CVE-2026-58643 MED 6.1 microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-58291 MED 6.1 microsoft edge_chromium Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-57258 MED 6.1 foxit pdf_editor The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes. 0.2%
CVE-2026-57257 MED 6.1 foxit pdf_editor During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes. 0.2%
CVE-2026-57255 MED 6.1 foxit pdf_editor The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds 0.2%
CVE-2026-57253 MED 6.1 foxit pdf_editor An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing. 0.2%
CVE-2026-57243 MED 6.1 foxit pdf_editor During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash. 0.2%
CVE-2026-57241 MED 6.1 foxit pdf_editor The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the appl 0.2%
CVE-2026-55898 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-54988 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-52760 MED 6.1 apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic 0.7%
CVE-2026-50661 MED 6.1 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2026-50495 MED 6.1 microsoft windows_10_1809 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-50453 MED 6.1 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5%
CVE-2026-50383 MED 6.1 microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50229 MED 6.1 apache tomcat Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 4.1%
CVE-2026-49174 MED 6.1 microsoft windows_10_1809 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-47887 MED 6.1 vmware spring_framework A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6. 0.2%