IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-58523 MED 6.5 microsoft edge_chromium Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. 0.9%
CVE-2026-58301 MED 6.5 apache shiro When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Ap 0.3%
CVE-2026-58279 MED 6.5 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-58160 MED 6.5 apache traffic_server Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, whic 0.4%
CVE-2026-57987 MED 6.5 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2026-57982 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-57979 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-57976 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-57259 MED 6.5 foxit pdf_editor The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, thro 0.4%
CVE-2026-57211 MED 6.5 broadcom rabbitmq_server RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple 0.6%
CVE-2026-57032 MED 6.5 juniper junos An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS). If an attempt is made t 0.4%
CVE-2026-57027 MED 6.5 juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is con 0.3%
CVE-2026-57020 MED 6.5 juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). On all QFX10000 platfo 0.3%
CVE-2026-57019 MED 6.5 juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is rec 0.3%
CVE-2026-56646 MED 6.5 microsoft edge_chromium Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2026-56434 MED 6.5 f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticate 0.4%
CVE-2026-56185 MED 6.5 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-56168 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-55970 MED 6.5 apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.5%
CVE-2026-55956 MED 6.5 apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 1.5%
CVE-2026-55955 MED 6.5 apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. 0.4%
CVE-2026-55054 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-55051 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0.9%
CVE-2026-55003 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-54126 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0.9%