56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.706 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-33558 | MED 5.3 | apache kafka Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is | 0.6% | — |
| CVE-2026-33557 | CRIT 9.1 | apache kafka A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without valida | 0.7% | — |
| CVE-2026-33523 | MED 6.5 | apache http_server HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0.4% | — |
| CVE-2026-33519 | CRIT 9.8 | esri portal_for_arcgis An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. | 0.3% | — |
| CVE-2026-33518 | CRIT 9.8 | esri portal_for_arcgis An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. | 0.3% | — |
| CVE-2026-3351 | MED 4.3 | canonical lxd Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server. | 0.1% | — |
| CVE-2026-33454 | CRIT 9.4 | apache camel The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direc | 0.6% | — |
| CVE-2026-33453 | CRIT 10.0 | apache camel Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when route | 6.2% | — |
| CVE-2026-33452 | MED 5.5 | absolute secure_access CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. | 0.1% | — |
| CVE-2026-33451 | HIGH 7.8 | absolute secure_access CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system. | 0.1% | — |
| CVE-2026-33414 | HIGH 7.8 | podman_project podman Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted st | 0.6% | — |
| CVE-2026-33267 | CRIT 10.0 | apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. | 0.4% | — |
| CVE-2026-33266 | HIGH 7.5 | apache openmeetings Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attac | 0.2% | — |
| CVE-2026-33264 | CRIT 9.8 | apache airflow A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution | 1.6% | — |
| CVE-2026-33227 | MED 4.3 | apache activemq Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing me | 0.4% | — |
| CVE-2026-3315 | HIGH 7.8 | assaabloy visionline Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from | 0.1% | — |
| CVE-2026-33120 | HIGH 8.8 | microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33119 | MED 5.4 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.3% | — |
| CVE-2026-33118 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-33117 | CRIT 9.1 | microsoft azure_sdk_for_java The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, | 0.5% | — |
| CVE-2026-33116 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2026-33115 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-33114 | HIGH 8.4 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-33113 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-33112 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 32.7% | — |