58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-7754 | HIGH 7.7 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism. | 0.3% | — |
| CVE-2026-69855 | HIGH 7.7 | microsoft azure_copilot Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-66310 | HIGH 7.7 | microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-52906 | HIGH 7.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of replaced Since commit 1f3e4142c0eb ("9p: convert to the new mount API"), v9fs_apply_options() applies parsed mount flags with |= onto flags al | 0.2% | — |
| CVE-2026-48447 | HIGH 7.7 | adobe lightroom Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions be | 0.2% | — |
| CVE-2026-48348 | HIGH 7.7 | adobe animate Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction | 0.2% | — |
| CVE-2026-48347 | HIGH 7.7 | adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera | 0.7% | — |
| CVE-2026-47937 | HIGH 7.7 | adobe acrobat Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit th | 0.3% | — |
| CVE-2026-47879 | HIGH 7.7 | vmware spring_cloud_gateway Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1. | 0.3% | — |
| CVE-2026-46123 | HIGH 7.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we poste | 0.2% | — |
| CVE-2026-45497 | HIGH 7.7 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-42832 | HIGH 7.7 | microsoft excel Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. | 0.3% | — |
| CVE-2026-33821 | HIGH 7.7 | microsoft dynamics_365_customer_insights Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32174 | HIGH 7.7 | microsoft azure_ai_bot_service Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-27913 | HIGH 7.7 | microsoft windows_server_2012 Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally. | 0.4% | — |
| CVE-2026-26147 | HIGH 7.7 | microsoft azure_stack_hci Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-20852 | HIGH 7.7 | microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-20804 | HIGH 7.7 | microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-20342 | HIGH 7.7 | A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker | 0.5% | — |
| CVE-2026-20167 | HIGH 7.7 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error ha | 0.3% | — |
| CVE-2026-20124 | HIGH 7.7 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is | 0.5% | — |
| CVE-2026-20105 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaus | 0.3% | — |
| CVE-2026-20100 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN con | 0.3% | — |
| CVE-2026-20049 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all | 0.3% | — |
| CVE-2026-20014 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the avail | 0.3% | — |