IT
57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.490 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-58299 HIGH 7.5 microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-58294 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-58292 HIGH 7.5 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-58290 HIGH 7.5 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-58276 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-58189 HIGH 7.5 apache traffic_server Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomme 0.4%
CVE-2026-58186 HIGH 7.5 apache traffic_server The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to 0.4%
CVE-2026-58181 HIGH 7.5 apache traffic_server The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to up 0.4%
CVE-2026-58180 HIGH 7.5 apache traffic_server The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to versio 0.4%
CVE-2026-58178 HIGH 7.5 apache traffic_server The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to 0.4%
CVE-2026-58175 HIGH 7.5 apache traffic_server Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, whic 0.4%
CVE-2026-58164 HIGH 7.5 apache traffic_server Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to 0.4%
CVE-2026-58163 HIGH 7.5 apache traffic_server Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgr 0.4%
CVE-2026-58161 HIGH 7.5 apache traffic_server Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad 0.4%
CVE-2026-58151 HIGH 7.5 apache traffic_server Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended 0.5%
CVE-2026-57992 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57986 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57984 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57975 HIGH 7.5 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-57819 HIGH 7.5 apache cxf Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large n 0.5%
CVE-2026-57111 HIGH 7.5 apache helix Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read r 0.3%
CVE-2026-57108 HIGH 7.5 microsoft .net Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. 1.1%
CVE-2026-57089 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-57026 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is e 0.5%
CVE-2026-57023 HIGH 7.5 juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When 0.5%