57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-59322 | MED 6.3 | vmware spring_integration The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with Mu | 0.2% | — |
| CVE-2026-58543 | MED 6.3 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.2% | — |
| CVE-2026-57973 | MED 6.3 | microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. | 0.2% | — |
| CVE-2026-55145 | MED 6.3 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | 0.5% | — |
| CVE-2026-5273 | MED 6.3 | google chrome Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-50544 | MED 6.3 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and i | 0.1% | — |
| CVE-2026-50375 | MED 6.3 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50374 | MED 6.3 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.3% | — |
| CVE-2026-47910 | MED 6.3 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended ac | 0.1% | — |
| CVE-2026-47909 | MED 6.3 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended | 0.1% | — |
| CVE-2026-47861 | MED 6.3 | vmware spring_integration An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integrat | 0.3% | — |
| CVE-2026-47856 | MED 6.3 | vmware spring_integration Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integrati | 0.2% | — |
| CVE-2026-44911 | MED 6.3 | apache nifi Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users wit | 0.5% | — |
| CVE-2026-41610 | MED 6.3 | microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.6% | — |
| CVE-2026-34626 | MED 6.3 | adobe acrobat Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the conte | 0.3% | — |
| CVE-2026-28712 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.1% | — |
| CVE-2026-28711 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.1% | — |
| CVE-2026-27299 | MED 6.3 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation o | 0.2% | — |
| CVE-2026-20220 | MED 6.3 | cisco crosswork_network_controller A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in | 0.3% | — |
| CVE-2026-11308 | MED 6.3 | google chrome Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low) | 0.1% | — |
| CVE-2026-11187 | MED 6.3 | google chrome Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-11184 | MED 6.3 | google chrome Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-11181 | MED 6.3 | google chrome Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2025-66249 | MED 6.3 | apache livy Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the | 0.6% | — |
| CVE-2025-64408 | MED 6.3 | apache causeway Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authentic | 10.8% | — |