57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.490 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-58299 | HIGH 7.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-58294 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58292 | HIGH 7.5 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-58290 | HIGH 7.5 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.4% | — |
| CVE-2026-58276 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-58189 | HIGH 7.5 | apache traffic_server Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomme | 0.4% | — |
| CVE-2026-58186 | HIGH 7.5 | apache traffic_server The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | 0.4% | — |
| CVE-2026-58181 | HIGH 7.5 | apache traffic_server The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to up | 0.4% | — |
| CVE-2026-58180 | HIGH 7.5 | apache traffic_server The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to versio | 0.4% | — |
| CVE-2026-58178 | HIGH 7.5 | apache traffic_server The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to | 0.4% | — |
| CVE-2026-58175 | HIGH 7.5 | apache traffic_server Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, whic | 0.4% | — |
| CVE-2026-58164 | HIGH 7.5 | apache traffic_server Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | 0.4% | — |
| CVE-2026-58163 | HIGH 7.5 | apache traffic_server Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgr | 0.4% | — |
| CVE-2026-58161 | HIGH 7.5 | apache traffic_server Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrad | 0.4% | — |
| CVE-2026-58151 | HIGH 7.5 | apache traffic_server Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | 0.5% | — |
| CVE-2026-57992 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-57986 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-57984 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-57975 | HIGH 7.5 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-57819 | HIGH 7.5 | apache cxf Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing requests with very large n | 0.5% | — |
| CVE-2026-57111 | HIGH 7.5 | apache helix Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read r | 0.3% | — |
| CVE-2026-57108 | HIGH 7.5 | microsoft .net Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-57089 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-57026 | HIGH 7.5 | juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is e | 0.5% | — |
| CVE-2026-57023 | HIGH 7.5 | juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When | 0.5% | — |