57.484 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.484 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-61363 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-61352 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-60023 | HIGH 7.5 | apache answer Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the paren | 0.4% | — |
| CVE-2026-59878 | HIGH 7.5 | apache activemq Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause | 0.5% | — |
| CVE-2026-59841 | HIGH 7.5 | fortinet fortisiem A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here> | 0.2% | — |
| CVE-2026-59836 | HIGH 7.5 | fortinet forticlientems A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | 0.2% | — |
| CVE-2026-59780 | HIGH 7.5 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigura | 0.3% | — |
| CVE-2026-59762 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. T | 0.6% | — |
| CVE-2026-59657 | HIGH 7.5 | apache cloudstack Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to ver | 0.2% | — |
| CVE-2026-59655 | HIGH 7.5 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. | 0.3% | — |
| CVE-2026-59654 | HIGH 7.5 | apache cloudstack Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to e | 0.3% | — |
| CVE-2026-59289 | HIGH 7.5 | vmware spring_for_graphql Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memor | 0.3% | — |
| CVE-2026-59282 | HIGH 7.5 | vmware spring_framework Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring | 0.3% | — |
| CVE-2026-59173 | HIGH 7.5 | apache traffic_server Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. | 0.7% | — |
| CVE-2026-59134 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-59132 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2026-59117 | HIGH 7.5 | microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58627 | HIGH 7.5 | microsoft windows_10_1607 Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-58531 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-58389 | HIGH 7.5 | apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0.6% | — |
| CVE-2026-58299 | HIGH 7.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-58294 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58292 | HIGH 7.5 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-58290 | HIGH 7.5 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-58276 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |