56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.705 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-41280 | MED 4.9 | apache dolphinscheduler Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which | 0.4% | — |
| CVE-2026-41227 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Te | 0.3% | — |
| CVE-2026-41225 | CRIT 9.1 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Suppo | 0.3% | — |
| CVE-2026-41219 | MED 6.5 | f5 big-ip_access_policy_manager An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.3% | — |
| CVE-2026-41218 | HIGH 7.5 | f5 big-ip_access_policy_manager When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: | 0.3% | — |
| CVE-2026-41217 | HIGH 7.9 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a s | 0.1% | — |
| CVE-2026-41154 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB | 0.2% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0.4% | — |
| CVE-2026-41115 | MED 4.3 | apache kafka An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka | 0.3% | — |
| CVE-2026-41109 | HIGH 8.8 | microsoft visual_studio_code Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2026-41108 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41107 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-41106 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-41105 | HIGH 8.1 | microsoft azure_monitor_action_group_notification_system Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-41104 | CRIT 10.0 | microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-41103 | CRIT 9.1 | microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | 5.4% | — |
| CVE-2026-41102 | HIGH 7.1 | microsoft powerpoint Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | 0.3% | — |
| CVE-2026-41101 | HIGH 7.1 | microsoft word Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 0.3% | — |
| CVE-2026-41100 | MED 4.4 | microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | 0.2% | — |
| CVE-2026-41098 | HIGH 8.4 | microsoft azure_stack_edge Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2026-41097 | MED 6.7 | microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.4% | — |
| CVE-2026-41096 | CRIT 9.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2026-41095 | HIGH 7.8 | microsoft windows_server_2012 Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-41094 | HIGH 8.8 | microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-41092 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | 0.3% | — |