58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-89275 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-88773 | CRIT 10.0 | citrix netscaler_application_delivery_controller Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 a | 0.4% | — |
| CVE-2026-85889 | CRIT 10.0 | microsoft azure_ai_foundry Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-84412 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-83944 | CRIT 10.0 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-76460 | CRIT 10.0 | cisco identity_services_engine A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this v | 14.0% | |
| CVE-2026-76423 | CRIT 10.0 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authori | 0.6% | — |
| CVE-2026-76197 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit | 3.5% | — |
| CVE-2026-76195 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit | 3.5% | — |
| CVE-2026-76193 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitatio | 1.3% | — |
| CVE-2026-75723 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this | 1.2% | — |
| CVE-2026-75721 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-75703 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-75699 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-73369 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb | 1.2% | — |
| CVE-2026-70200 | CRIT 10.0 | microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69865 | CRIT 10.0 | microsoft azure_container_registry Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-69843 | CRIT 10.0 | microsoft fabric Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-69836 | CRIT 10.0 | microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | 1.5% | — |
| CVE-2026-69555 | CRIT 10.0 | microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-69502 | CRIT 10.0 | microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-69399 | CRIT 10.0 | microsoft azure_arc Azure Arc Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-66803 | CRIT 10.0 | microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-65816 | CRIT 10.0 | microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-65801 | CRIT 10.0 | microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |