IT
56.672 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.672 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-33102 CRIT 9.3 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-32210 CRIT 9.3 microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-27246 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27245 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27243 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-24307 CRIT 9.3 microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-24305 CRIT 9.3 microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability 0.5%
CVE-2026-21264 CRIT 9.3 microsoft account Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-14973 CRIT 9.3 ibm aspera IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. 0.5%
CVE-2026-11707 CRIT 9.3 ibm tivoli_system_automation_application_manager IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. 0.2%
CVE-2025-59286 CRIT 9.3 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-59272 CRIT 9.3 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. 0.5%
CVE-2025-59252 CRIT 9.3 microsoft 365_word_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-55321 CRIT 9.3 microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-49553 CRIT 9.3 adobe connect Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that 0.6%
CVE-2025-38560 CRIT 9.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory validation An SNP cache coherency vulnerability requires a cache line eviction mitigation when validating memory after a page state change to pri 0.2%
CVE-2025-32711 CRIT 9.3 microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 8.0%
CVE-2025-29814 CRIT 9.3 microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. 2.2%
CVE-2025-22224 CRIT 9.3 vmware cloud_foundation VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach 1.6%
CVE-2024-57793 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virt: tdx-guest: Just leak decrypted memory on unrecoverable errors In CoCo VMs it is possible for the untrusted host to cause set_memory_decrypted() to fail such that an error is returned a 0.2%
CVE-2024-49147 CRIT 9.3 microsoft update_catalog Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. 1.3%
CVE-2024-49038 CRIT 9.3 microsoft copilot_studio Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. 1.0%
CVE-2024-38108 CRIT 9.3 microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability 1.2%
CVE-2024-36913 CRIT 9.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that a 0.7%
CVE-2024-36909 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail 0.2%