IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-7754 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism. 0.3% —
CVE-2026-69855 HIGH 7.7 microsoft azure_copilot Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. 0.8% —
CVE-2026-66310 HIGH 7.7 microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4% —
CVE-2026-52906 HIGH 7.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of replaced Since commit 1f3e4142c0eb ("9p: convert to the new mount API"), v9fs_apply_options() applies parsed mount flags with |= onto flags al 0.2% —
CVE-2026-48447 HIGH 7.7 adobe lightroom Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions be 0.2% —
CVE-2026-48348 HIGH 7.7 adobe animate Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction 0.2% —
CVE-2026-48347 HIGH 7.7 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0.7% —
CVE-2026-47937 HIGH 7.7 adobe acrobat Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit th 0.3% —
CVE-2026-47879 HIGH 7.7 vmware spring_cloud_gateway Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1. 0.3% —
CVE-2026-46123 HIGH 7.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we poste 0.2% —
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0.6% —
CVE-2026-42832 HIGH 7.7 microsoft excel Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. 0.3% —
CVE-2026-33821 HIGH 7.7 microsoft dynamics_365_customer_insights Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-32174 HIGH 7.7 microsoft azure_ai_bot_service Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-27913 HIGH 7.7 microsoft windows_server_2012 Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally. 0.4% —
CVE-2026-26147 HIGH 7.7 microsoft azure_stack_hci Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. 1.0% —
CVE-2026-20852 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5% —
CVE-2026-20804 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5% —
CVE-2026-20342 HIGH 7.7 A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker 0.5% —
CVE-2026-20167 HIGH 7.7 cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error ha 0.3% —
CVE-2026-20124 HIGH 7.7 cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is 0.5% —
CVE-2026-20105 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaus 0.3% —
CVE-2026-20100 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN con 0.3% —
CVE-2026-20049 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all 0.3% —
CVE-2026-20014 HIGH 7.7 cisco adaptive_security_appliance_software A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the avail 0.3% —