IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.742 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-23918 HIGH 8.8 apache http_server Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. 49.7%
CVE-2026-23907 MED 5.3 apache pdfbox This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComp 0.9%
CVE-2026-23906 CRIT 9.8 apache druid Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits an 1.0%
CVE-2026-23904 HIGH 7.3 apache kyuubi Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in 0.5%
CVE-2026-23903 MED 5.3 apache shiro Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served f 0.3%
CVE-2026-23902 HIGH 8.1 apache dolphinscheduler Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior 0.4%
CVE-2026-23901 LOW 2.5 apache shiro Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs 0.2%
CVE-2026-23889 MED 6.5 pnpm pnpm pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Win 0.4%
CVE-2026-23795 MED 4.9 apache syncope Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby caus 1.9%
CVE-2026-23794 MED 6.8 apache syncope Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, f 0.5%
CVE-2026-23708 HIGH 7.5 fortinet fortisoar A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authe 0.3%
CVE-2026-23674 HIGH 7.5 microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 1.2%
CVE-2026-23673 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-23672 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4%
CVE-2026-23671 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-23670 MED 5.7 microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-23669 HIGH 8.8 microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-23668 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2026-23667 HIGH 7.0 microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-23666 HIGH 7.5 microsoft .net_framework Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. 1.3%
CVE-2026-23665 HIGH 7.8 microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-23664 HIGH 7.5 microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-23662 HIGH 7.5 microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-23661 HIGH 7.5 microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0.7%