IT
56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-42826 CRIT 10.0 microsoft azure_devops Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-42822 CRIT 10.0 microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-41104 CRIT 10.0 microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-40412 CRIT 10.0 microsoft azure_orbital_spatio Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-35431 CRIT 10.0 microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-33819 CRIT 10.0 microsoft bing Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-33453 CRIT 10.0 apache camel Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when route 6.2%
CVE-2026-33267 CRIT 10.0 apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. 0.3%
CVE-2026-33107 CRIT 10.0 microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-33105 CRIT 10.0 microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-32213 CRIT 10.0 microsoft azure_ai_foundry Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 0.9%
CVE-2026-32186 CRIT 10.0 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-32169 CRIT 10.0 microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-23652 CRIT 10.0 microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-20223 CRIT 10.0 cisco secure_workload A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient 0.8%
CVE-2026-20182 CRIT 10.0 cisco catalyst_sd-wan_manager May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The sect 91.5%
CVE-2026-20131 CRIT 10.0 ransomware cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to i 31.2%
CVE-2026-20127 CRIT 10.0 cisco catalyst_sd-wan_manager A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remot 88.2%
CVE-2026-13782 CRIT 10.0 google chrome Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) 0.3%
CVE-2025-9588 CRIT 10.0 ironmountain envision Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563. 1.1%
CVE-2025-65041 CRIT 10.0 microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-65037 CRIT 10.0 microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-59503 CRIT 10.0 microsoft azure_compute_resource_provider Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-57870 CRIT 10.0 esri arcgis_server A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service opera 0.5%
CVE-2025-55241 CRIT 10.0 microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability 1.6%