58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-29168 | HIGH 7.3 | apache http_server Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the | 0.6% | — |
| CVE-2026-28722 | HIGH 7.3 | acronis cyber_protect Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.2% | — |
| CVE-2026-28721 | HIGH 7.3 | acronis cyber_protect Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.2% | — |
| CVE-2026-24206 | HIGH 7.3 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure. | 0.5% | — |
| CVE-2026-23904 | HIGH 7.3 | apache kyuubi Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in | 0.5% | — |
| CVE-2026-23236 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the mem | 0.2% | — |
| CVE-2026-23161 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix race of truncate and swap entry split The helper for shmem swap freeing is not handling the order of swap entries correctly. It uses xa_cmpxchg_irq to erase the swap ent | 0.1% | — |
| CVE-2026-21916 | HIGH 7.3 | juniper junos A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a | 0.1% | — |
| CVE-2026-21733 | HIGH 7.3 | imaginationtech ddk Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protections. | 0.1% | — |
| CVE-2026-21248 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.3% | — |
| CVE-2026-21247 | HIGH 7.3 | microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-21244 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.3% | — |
| CVE-2026-21235 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2026-20151 | HIGH 7.3 | cisco smart_software_manager_on-prem A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user in | 0.3% | — |
| CVE-2026-18639 | HIGH 7.3 | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually veri | 0.3% | — |
| CVE-2026-13476 | HIGH 7.3 | ibm informix_dynamic_server IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | 0.5% | — |
| CVE-2026-11980 | HIGH 7.3 | ibm aspera IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. | 0.1% | — |
| CVE-2026-11115 | HIGH 7.3 | google chrome Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | 0.1% | — |
| CVE-2026-10845 | HIGH 7.3 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications. | 0.5% | — |
| CVE-2025-7024 | HIGH 7.3 | airbus tetra_connectivity_server Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the v | 0.1% | — |
| CVE-2025-62565 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-61735 | HIGH 7.3 | apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5. | 0.5% | — |
| CVE-2025-59504 | HIGH 7.3 | microsoft azure_monitor_agent Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2025-59273 | HIGH 7.3 | microsoft azure_event_grid Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2025-59118 | HIGH 7.3 | apache ofbiz Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. | 1.6% | — |