IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-31477 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leaks and NULL deref in smb2_lock() smb2_lock() has three error handling issues after list_del() detaches smb_lock from lock_list at no_check_cl: 1) If vfs_lock_file() ret 0.5% —
CVE-2026-31467 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: erofs: add GFP_NOIO in the bio completion if needed The bio completion path in the process context (e.g. dm-verity) will directly call into decompression rather than trigger another workqueu 0.4% —
CVE-2026-31417 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging `fragment_queue` in `x2 0.4% —
CVE-2026-30912 HIGH 7.5 apache airflow In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, wh 0.4% —
CVE-2026-3087 HIGH 7.5 python python If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this v 0.6% —
CVE-2026-30798 HIGH 7.5 rustdesk rustdesk Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protoc 0.3% —
CVE-2026-30796 HIGH 7.5 rustdesk rustdesk_server Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attac 0.4% —
CVE-2026-30795 HIGH 7.5 rustdesk rustdesk Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files s 0.3% —
CVE-2026-30791 HIGH 7.5 rustdesk rustdesk Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Dat 0.2% —
CVE-2026-30778 HIGH 7.5 apache skywalking The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue. 0.5% —
CVE-2026-29169 HIGH 7.5 apache http_server A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was m 0.6% —
CVE-2026-29146 HIGH 7.5 apache tomcat Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0. 8.8% —
CVE-2026-29129 HIGH 7.5 apache tomcat Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 0.3% —
CVE-2026-28814 HIGH 7.5 apache jspwiki Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. 0.4% —
CVE-2026-28811 HIGH 7.5 apache jspwiki Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. 0.5% —
CVE-2026-28779 HIGH 7.5 apache airflow Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tok 0.7% —
CVE-2026-28718 HIGH 7.5 acronis cyber_protect Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. 0.3% —
CVE-2026-27651 HIGH 7.5 f5 nginx_open_source When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server p 0.9% —
CVE-2026-26171 HIGH 7.5 microsoft .net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. 1.8% —
CVE-2026-26164 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8% —
CVE-2026-26154 HIGH 7.5 microsoft windows_server_2012 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. 1.1% —
CVE-2026-26144 HIGH 7.5 microsoft 365_apps Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 1.2% —
CVE-2026-26130 HIGH 7.5 microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 2.8% —
CVE-2026-26129 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.1% —
CVE-2026-26127 HIGH 7.5 microsoft .net Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. 2.0% —