IT
56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-65667 CRIT 10.0 microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-63795 CRIT 10.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been 0.5%
CVE-2026-63508 CRIT 10.0 microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-62825 CRIT 10.0 microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-58630 CRIT 10.0 microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. 0.9%
CVE-2026-58275 CRIT 10.0 microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-58162 CRIT 10.0 apache traffic_server The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upg 0.3%
CVE-2026-58150 CRIT 10.0 apache traffic_server Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended 0.3%
CVE-2026-57834 CRIT 10.0 apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 0.3%
CVE-2026-57106 CRIT 10.0 microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. 0.9%
CVE-2026-56191 CRIT 10.0 microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. 0.7%
CVE-2026-56163 CRIT 10.0 microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.9%
CVE-2026-56162 CRIT 10.0 microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2026-48449 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. 0.5%
CVE-2026-48331 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. 0.5%
CVE-2026-48330 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v 0.7%
CVE-2026-48323 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to 0.6%
CVE-2026-48303 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter 0.6%
CVE-2026-48286 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter 0.9%
CVE-2026-47938 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. 0.4%
CVE-2026-47280 CRIT 10.0 microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-45480 CRIT 10.0 microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-42901 CRIT 10.0 microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. 0.3%