IT
56.713 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.713 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-28710 CRIT 9.8 acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. 0.4%
CVE-2026-28709 MED 4.3 acronis cyber_protect Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. 0.2%
CVE-2026-28672 CRIT 9.8 apache ranger Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. 1.3%
CVE-2026-28563 MED 4.3 apache airflow Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authoriz 0.4%
CVE-2026-28373 CRIT 9.6 stackfield stackfield The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesys 0.4%
CVE-2026-2813 MED 4.7 esri arcgis_server ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to a 0.3%
CVE-2026-2812 MED 5.3 esri arcgis_server ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of t 0.4%
CVE-2026-27931 MED 5.5 microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-27930 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-27929 HIGH 7.0 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27928 HIGH 8.7 microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-27927 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27926 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27925 MED 6.5 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. 0.4%
CVE-2026-27924 HIGH 7.8 microsoft windows_10_21h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27923 HIGH 7.8 microsoft windows_10_1607 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27922 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27921 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2026-27920 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27919 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27918 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27917 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27916 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27915 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-27914 HIGH 7.8 microsoft windows_10_1607 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. 2.6%