56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.705 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-45169 | HIGH 8.6 | paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an | 0.4% | — |
| CVE-2026-45112 | HIGH 7.5 | apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 1.1% | — |
| CVE-2026-44930 | CRIT 9.8 | apache cxf An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix th | 0.7% | — |
| CVE-2026-44915 | MED 6.1 | apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are | 0.6% | — |
| CVE-2026-44914 | HIGH 7.2 | apache nifi Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required | 0.7% | — |
| CVE-2026-44913 | HIGH 7.2 | apache nifi Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potent | 0.6% | — |
| CVE-2026-44911 | MED 6.3 | apache nifi Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users wit | 0.5% | — |
| CVE-2026-44825 | HIGH 8.1 | apache solr Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials instal | 2.9% | — |
| CVE-2026-44824 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44823 | HIGH 7.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-44822 | HIGH 8.2 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-44821 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-44820 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-4482 | MED 5.5 | rapid7 insight_agent The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exp | 0.1% | — |
| CVE-2026-44819 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44818 | HIGH 7.0 | microsoft 365_apps Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-44817 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-44815 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-44814 | MED 5.5 | microsoft windows_11_26h1 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-44813 | HIGH 7.8 | microsoft windows_11_26h1 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44812 | HIGH 7.8 | microsoft excel Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-44811 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44810 | HIGH 8.4 | microsoft windows_11_23h2 Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44809 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44808 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |