57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-68970 | MED 6.5 | apache airflow Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string | 0.2% | — |
| CVE-2026-68969 | MED 6.5 | apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level | 0.4% | — |
| CVE-2026-68872 | MED 6.5 | apache apache-airflow-providers-amazon The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo | 0.3% | — |
| CVE-2026-68871 | MED 6.5 | apache apache-airflow-providers-apache-yandex The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in | 0.3% | — |
| CVE-2026-68868 | MED 6.5 | apache apache-airflow-providers-google The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every | 0.5% | — |
| CVE-2026-68080 | MED 6.5 | apache qpid_broker-j It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are | 0.4% | — |
| CVE-2026-68078 | MED 6.5 | apache qpid_broker-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users ar | 0.4% | — |
| CVE-2026-68077 | MED 6.5 | apache qpid_broker-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgr | 0.4% | — |
| CVE-2026-68075 | MED 6.5 | apache qpid_broker-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. | 0.4% | — |
| CVE-2026-67591 | MED 6.5 | apache qpid_protonj2 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | 0.4% | — |
| CVE-2026-67555 | MED 6.5 | apache qpid_proton-dotnet It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users | 0.4% | — |
| CVE-2026-67554 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to | 0.4% | — |
| CVE-2026-67553 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | 0.4% | — |
| CVE-2026-66391 | MED 6.5 | apache wicket Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the is | 0.4% | — |
| CVE-2026-66326 | MED 6.5 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-66324 | MED 6.5 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-66314 | MED 6.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-66301 | MED 6.5 | microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-66277 | MED 6.5 | apache qpid_proton-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users ar | 0.4% | — |
| CVE-2026-66276 | MED 6.5 | apache qpid_proton-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgr | 0.4% | — |
| CVE-2026-66275 | MED 6.5 | apache qpid_proton-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | 0.4% | — |
| CVE-2026-65945 | MED 6.5 | apache ranger Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.4% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-65806 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | 0.6% | — |