56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.736 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-33113 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-33112 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 32.7% | — |
| CVE-2026-33111 | HIGH 7.5 | microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2026-33110 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33107 | CRIT 10.0 | microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-33105 | CRIT 10.0 | microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-33104 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33103 | MED 5.5 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | 0.2% | — |
| CVE-2026-33102 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-33101 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33100 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33099 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33098 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-33096 | HIGH 7.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-33095 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-33007 | MED 5.3 | apache http_server A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fix | 0.5% | — |
| CVE-2026-33006 | MED 4.8 | apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 0.6% | — |
| CVE-2026-33005 | MED 4.3 | apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name an | 0.4% | — |
| CVE-2026-32990 | MED 5.3 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade | 0.3% | — |
| CVE-2026-32967 | CRIT 9.1 | apache dolphinscheduler Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.3% | — |
| CVE-2026-32966 | CRIT 9.8 | apache dolphinscheduler DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.4% | — |
| CVE-2026-32952 | MED 5.3 | microsoft go-ntlmssp go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport | 1.0% | — |
| CVE-2026-32948 | HIGH 7.8 | scala.epfl sbt sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definitio | 0.3% | — |
| CVE-2026-32794 | MED 4.8 | apache airflow_providers_databricks Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulat | 0.4% | — |