IT
58.151 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.151 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2005-1794 HIGH 7.4 microsoft remote_desktop_connection Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks. 16.3%
CVE-2026-8835 HIGH 7.3 ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service. 0.3%
CVE-2026-70355 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-69477 HIGH 7.3 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. 0.4%
CVE-2026-69417 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-69402 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-68821 HIGH 7.3 microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-67260 HIGH 7.3 apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug 0.8%
CVE-2026-65948 HIGH 7.3 apache ranger UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0.3%
CVE-2026-64900 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-64158 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O_RDWR In netfs_perform_write(), "write streaming" (the caching of dirty data in dirty but !uptodate folios) is performed to avoid the need 0.1%
CVE-2026-64126 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising Data length MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command, with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. 0.1%
CVE-2026-62914 HIGH 7.3 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2026-60080 HIGH 7.3 apache fory Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommen 0.7%
CVE-2026-59119 HIGH 7.3 microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-58640 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 0.4%
CVE-2026-57028 HIGH 7.3 juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which shoul 0.3%
CVE-2026-56624 HIGH 7.3 apache mina_sshd Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not chec 0.3%
CVE-2026-55957 HIGH 7.3 apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- 2.9%
CVE-2026-55126 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2026-55034 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.9%
CVE-2026-55021 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.9%
CVE-2026-53404 HIGH 7.3 apache tomcat Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, 0.6%
CVE-2026-50482 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 0.4%
CVE-2026-50364 HIGH 7.3 microsoft windows_10_21h2 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. 0.5%