56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.663 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-45462 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-45461 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45460 | MED 4.7 | microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-45459 | LOW 3.3 | microsoft 365_apps Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-45458 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45457 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45456 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-45454 | MED 6.5 | microsoft sharepoint_server Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.6% | — |
| CVE-2026-45453 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-45434 | CRIT 9.8 | apache ofbiz Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 22.4% | — |
| CVE-2026-45426 | LOW 3.1 | apache airflow Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested | 0.4% | — |
| CVE-2026-45361 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advis | 0.6% | — |
| CVE-2026-45360 | HIGH 7.3 | apache airflow Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG a | 0.7% | — |
| CVE-2026-45249 | MED 6.1 | apache echarts A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-speci | 0.7% | — |
| CVE-2026-45205 | MED 5.3 | apache commons_configuration Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are re | 0.5% | — |
| CVE-2026-45203 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in m | 0.1% | — |
| CVE-2026-45196 | HIGH 7.8 | imaginationtech ddk Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation. | 0.1% | — |
| CVE-2026-45192 | MED 6.5 | apache airflow A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the | 0.4% | — |
| CVE-2026-45187 | MED 6.5 | apache ofbiz Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2026-45178 | HIGH 8.1 | paloaltonetworks idira_secrets_manager Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve un | 0.4% | — |
| CVE-2026-45177 | CRIT 9.1 | paloaltonetworks idira_secrets_manager_edge Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, | 0.5% | — |
| CVE-2026-45176 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Un | 0.1% | — |
| CVE-2026-45175 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumst | 0.1% | — |
| CVE-2026-45174 | HIGH 7.8 | paloaltonetworks idira_endpoint_privilege_manager Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | 0.1% | — |