IT
56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.625 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-47341 MED 6.5 apache apisix Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recomme 0.4%
CVE-2026-47340 MED 6.5 apache dolphinscheduler Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, w 0.4%
CVE-2026-47339 HIGH 8.1 apache apisix Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3 0.3%
CVE-2026-47323 CRIT 9.8 apache camel Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilt 1.5%
CVE-2026-47305 HIGH 7.8 microsoft visual_studio_2022 Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-47304 HIGH 8.1 microsoft .net Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.2%
CVE-2026-47303 HIGH 8.8 microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-47302 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 1.0%
CVE-2026-47301 HIGH 8.8 microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-47300 HIGH 8.8 microsoft .net Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-47299 HIGH 7.2 microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-47298 HIGH 8.0 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-47296 HIGH 7.5 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-47295 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-47294 HIGH 8.0 microsoft sharepoint_server Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-47293 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-47292 HIGH 7.8 microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-47291 CRIT 9.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. 22.8%
CVE-2026-47290 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-47289 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2026-47288 HIGH 7.1 microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. 0.5%
CVE-2026-47287 MED 6.5 microsoft visual_studio_code Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0.8%
CVE-2026-47285 MED 6.5 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-47284 MED 6.5 microsoft visual_studio_code Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-47282 MED 6.5 microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.6%