57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-35562 | HIGH 7.5 | amazon athena_odbc Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's pa | 0.4% | — |
| CVE-2026-35424 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-34711 | HIGH 7.5 | adobe c2pa CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploita | 0.4% | — |
| CVE-2026-34502 | HIGH 7.5 | apache apr-util Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | 0.5% | — |
| CVE-2026-34501 | HIGH 7.5 | apache apr-util Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | 0.5% | — |
| CVE-2026-34487 | HIGH 7.5 | apache tomcat Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1 | 0.4% | — |
| CVE-2026-34486 | HIGH 7.5 | apache tomcat Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0 | 98.6% | |
| CVE-2026-34483 | HIGH 7.5 | apache tomcat Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended t | 0.5% | — |
| CVE-2026-34481 | HIGH 7.5 | apache log4j Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinit | 0.7% | — |
| CVE-2026-34480 | HIGH 7.5 | apache log4j Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing inva | 1.0% | — |
| CVE-2026-34479 | HIGH 7.5 | apache log4j The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, w | 0.5% | — |
| CVE-2026-34478 | HIGH 7.5 | apache log4j Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attr | 1.0% | — |
| CVE-2026-34356 | HIGH 7.5 | apache http_server Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the is | 0.7% | — |
| CVE-2026-34355 | HIGH 7.5 | apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | 1.2% | — |
| CVE-2026-34059 | HIGH 7.5 | apache http_server Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0.4% | — |
| CVE-2026-34020 | HIGH 7.5 | apache openmeetings Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue aff | 0.5% | — |
| CVE-2026-33790 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continu | 0.3% | — |
| CVE-2026-33778 | HIGH 7.5 | juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service ( | 0.3% | — |
| CVE-2026-33266 | HIGH 7.5 | apache openmeetings Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attac | 0.2% | — |
| CVE-2026-33116 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2026-33111 | HIGH 7.5 | microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2026-33096 | HIGH 7.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-32228 | HIGH 7.5 | apache airflow UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. | 0.4% | — |
| CVE-2026-32203 | HIGH 7.5 | microsoft .net Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | 1.9% | — |
| CVE-2026-32178 | HIGH 7.5 | microsoft .net Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | 2.3% | — |