57.436 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.436 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-73237 | MED 6.1 | apache allura XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | 0.4% | — |
| CVE-2026-66390 | MED 6.1 | apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, | 0.4% | — |
| CVE-2026-66325 | MED 6.1 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-65804 | MED 6.1 | microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-59281 | MED 6.1 | vmware spring_framework Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript | 0.2% | — |
| CVE-2026-5899 | MED 6.1 | google chrome Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium securit | 0.1% | — |
| CVE-2026-5896 | MED 6.1 | google chrome Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low) | 0.2% | — |
| CVE-2026-58643 | MED 6.1 | microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-58291 | MED 6.1 | microsoft edge_chromium Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-57258 | MED 6.1 | foxit pdf_editor The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes. | 0.2% | — |
| CVE-2026-57257 | MED 6.1 | foxit pdf_editor During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes. | 0.2% | — |
| CVE-2026-57255 | MED 6.1 | foxit pdf_editor The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds | 0.2% | — |
| CVE-2026-57253 | MED 6.1 | foxit pdf_editor An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing. | 0.2% | — |
| CVE-2026-57243 | MED 6.1 | foxit pdf_editor During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash. | 0.2% | — |
| CVE-2026-57241 | MED 6.1 | foxit pdf_editor The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the appl | 0.2% | — |
| CVE-2026-55898 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-54988 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-52760 | MED 6.1 | apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic | 0.7% | — |
| CVE-2026-50661 | MED 6.1 | microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2026-50495 | MED 6.1 | microsoft windows_10_1809 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 0.3% | — |
| CVE-2026-50453 | MED 6.1 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0.5% | — |
| CVE-2026-50383 | MED 6.1 | microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-50229 | MED 6.1 | apache tomcat Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through | 4.1% | — |
| CVE-2026-49174 | MED 6.1 | microsoft windows_10_1809 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 0.3% | — |
| CVE-2026-47887 | MED 6.1 | vmware spring_framework A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6. | 0.2% | — |