58.151 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.151 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-1794 | HIGH 7.4 | microsoft remote_desktop_connection Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks. | 16.3% | — |
| CVE-2026-8835 | HIGH 7.3 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service. | 0.3% | — |
| CVE-2026-70355 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-69477 | HIGH 7.3 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-69417 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-69402 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-68821 | HIGH 7.3 | microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-67260 | HIGH 7.3 | apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug | 0.8% | — |
| CVE-2026-65948 | HIGH 7.3 | apache ranger UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.3% | — |
| CVE-2026-64900 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2026-64158 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O_RDWR In netfs_perform_write(), "write streaming" (the caching of dirty data in dirty but !uptodate folios) is performed to avoid the need | 0.1% | — |
| CVE-2026-64126 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising Data length MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command, with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. | 0.1% | — |
| CVE-2026-62914 | HIGH 7.3 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 0.3% | — |
| CVE-2026-60080 | HIGH 7.3 | apache fory Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommen | 0.7% | — |
| CVE-2026-59119 | HIGH 7.3 | microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-58640 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-57028 | HIGH 7.3 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which shoul | 0.3% | — |
| CVE-2026-56624 | HIGH 7.3 | apache mina_sshd Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not chec | 0.3% | — |
| CVE-2026-55957 | HIGH 7.3 | apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- | 2.9% | — |
| CVE-2026-55126 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55034 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-55021 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-53404 | HIGH 7.3 | apache tomcat Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, | 0.6% | — |
| CVE-2026-50482 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-50364 | HIGH 7.3 | microsoft windows_10_21h2 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. | 0.5% | — |