IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.571 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2026-68971 MED 6.5 apache airflow Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manag 0.3%
CVE-2026-68970 MED 6.5 apache airflow Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string 0.2%
CVE-2026-68969 MED 6.5 apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level 0.4%
CVE-2026-68968 HIGH 7.5 apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative 0.4%
CVE-2026-68872 MED 6.5 apache apache-airflow-providers-amazon The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo 0.2%
CVE-2026-68871 MED 6.5 apache apache-airflow-providers-apache-yandex The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in 0.2%
CVE-2026-68868 MED 6.5 apache apache-airflow-providers-google The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every 0.4%
CVE-2026-68823 CRIT 9.1 microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-68821 HIGH 7.3 microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68819 MED 5.9 microsoft windows_10_1607 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2026-68817 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68816 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68815 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68814 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68813 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68812 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68811 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68810 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68809 MED 5.5 microsoft 365_apps Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-68808 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68807 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68806 HIGH 7.8 microsoft 365_apps Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68805 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68804 HIGH 7.8 microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68803 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%