IT
56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.736 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-33113 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-33112 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 32.7%
CVE-2026-33111 HIGH 7.5 microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2026-33110 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.0%
CVE-2026-33109 CRIT 9.9 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-33107 CRIT 10.0 microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-33105 CRIT 10.0 microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-33104 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33103 MED 5.5 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. 0.2%
CVE-2026-33102 CRIT 9.3 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-33101 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33100 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33099 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33098 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33096 HIGH 7.5 microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-33095 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-33007 MED 5.3 apache http_server A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fix 0.5%
CVE-2026-33006 MED 4.8 apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. 0.6%
CVE-2026-33005 MED 4.3 apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name an 0.4%
CVE-2026-32990 MED 5.3 apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade 0.3%
CVE-2026-32967 CRIT 9.1 apache dolphinscheduler Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0.3%
CVE-2026-32966 CRIT 9.8 apache dolphinscheduler DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0.4%
CVE-2026-32952 MED 5.3 microsoft go-ntlmssp go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport 1.0%
CVE-2026-32948 HIGH 7.8 scala.epfl sbt sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definitio 0.3%
CVE-2026-32794 MED 4.8 apache airflow_providers_databricks Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulat 0.4%