57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41602 | HIGH 7.5 | apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 1.2% | — |
| CVE-2026-41284 | HIGH 7.5 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affec | 0.8% | — |
| CVE-2026-41227 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Te | 0.3% | — |
| CVE-2026-41218 | HIGH 7.5 | f5 big-ip_access_policy_manager When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: | 0.3% | — |
| CVE-2026-41084 | HIGH 7.5 | apache airflow A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_id` extracted from re | 0.5% | — |
| CVE-2026-41007 | HIGH 7.5 | vmware spring_hateoas Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3. | 0.3% | — |
| CVE-2026-41006 | HIGH 7.5 | vmware spring_hateoas Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: S | 0.3% | — |
| CVE-2026-40988 | HIGH 7.5 | vmware spring_security An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: | 0.3% | — |
| CVE-2026-40981 | HIGH 7.5 | vmware spring_cloud_config When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclus | 0.4% | — |
| CVE-2026-40972 | HIGH 7.5 | vmware spring_boot An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, t | 0.3% | — |
| CVE-2026-40629 | HIGH 7.5 | f5 big-ip_access_policy_manager When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-40618 | HIGH 7.5 | f5 big-ip_access_policy_manager When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the | 0.3% | — |
| CVE-2026-40423 | HIGH 7.5 | f5 big-ip_access_policy_manager When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-40406 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-40405 | HIGH 7.5 | microsoft windows_11_24h2 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2026-40378 | HIGH 7.5 | microsoft windows_10_1607 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-40376 | HIGH 7.5 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-40067 | HIGH 7.5 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-40060 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.3% | — |
| CVE-2026-39458 | HIGH 7.5 | f5 big-ip_access_policy_manager When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have r | 0.3% | — |
| CVE-2026-39455 | HIGH 7.5 | f5 big-ip_access_policy_manager When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End o | 0.3% | — |
| CVE-2026-3932 | HIGH 7.5 | google chrome Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-39304 | HIGH 7.5 | apache activemq Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to | 0.9% | — |
| CVE-2026-3924 | HIGH 7.5 | google chrome use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-3598 | HIGH 7.5 | rustdesk rustdesk_server Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerab | 0.2% | — |