IT
56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.663 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-47618 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. 0.3%
CVE-2026-47617 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. 0.3%
CVE-2026-47616 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. 0.3%
CVE-2026-47615 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. 0.3%
CVE-2026-47614 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. 0.3%
CVE-2026-47613 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to informa 0.3%
CVE-2026-47612 HIGH 7.5 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. 0.6%
CVE-2026-47487 MED 4.4 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vu 0.2%
CVE-2026-47430 HIGH 7.5 apache cordova_inappbrowser ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside t 0.7%
CVE-2026-47359 HIGH 8.8 apache cloudstack Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.2 0.5%
CVE-2026-47342 HIGH 8.8 apache ofbiz A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. 0.4%
CVE-2026-47341 MED 6.5 apache apisix Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recomme 0.4%
CVE-2026-47340 MED 6.5 apache dolphinscheduler Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, w 0.4%
CVE-2026-47339 HIGH 8.1 apache apisix Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3 0.3%
CVE-2026-47323 CRIT 9.8 apache camel Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilt 1.5%
CVE-2026-47305 HIGH 7.8 microsoft visual_studio_2022 Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-47304 HIGH 8.1 microsoft .net Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.2%
CVE-2026-47303 HIGH 8.8 microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-47302 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 1.0%
CVE-2026-47301 HIGH 8.8 microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-47300 HIGH 8.8 microsoft .net Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-47299 HIGH 7.2 microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-47298 HIGH 8.0 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-47296 HIGH 7.5 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-47295 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.9%