57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-75005 | HIGH 7.5 | apache apisix Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upg | 0.8% | — |
| CVE-2026-74848 | HIGH 7.5 | apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache | 0.6% | — |
| CVE-2026-73635 | HIGH 7.5 | apache struts Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the frame | 0.5% | — |
| CVE-2026-73634 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request | 0.4% | — |
| CVE-2026-73633 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single re | 0.6% | — |
| CVE-2026-7357 | HIGH 7.5 | google chrome Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-7349 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-7343 | HIGH 7.5 | google chrome Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0.2% | — |
| CVE-2026-7338 | HIGH 7.5 | google chrome Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High) | 0.2% | — |
| CVE-2026-73017 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-71559 | HIGH 7.5 | apache fory Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache F | 0.4% | — |
| CVE-2026-71257 | HIGH 7.5 | apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f | 0.8% | — |
| CVE-2026-70065 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69804 | HIGH 7.5 | microsoft sharepoint_server Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-69342 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-68981 | HIGH 7.5 | apache nifi Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing | 0.5% | — |
| CVE-2026-68968 | HIGH 7.5 | apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative | 0.4% | — |
| CVE-2026-68763 | HIGH 7.5 | apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 throu | 0.8% | — |
| CVE-2026-68481 | HIGH 7.5 | apache cxf In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST | 0.4% | — |
| CVE-2026-68074 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes th | 0.5% | — |
| CVE-2026-68073 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the iss | 0.5% | — |
| CVE-2026-68060 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fix | 0.5% | — |
| CVE-2026-67592 | HIGH 7.5 | apache qpid_protonj2 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are | 0.5% | — |
| CVE-2026-67590 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue | 0.5% | — |
| CVE-2026-67589 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes | 0.5% | — |