56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.742 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43117 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment wil | 0.4% | — |
| CVE-2026-43083 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue- | 0.4% | — |
| CVE-2026-43071 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b3 | 0.4% | — |
| CVE-2026-42833 | CRIT 9.1 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42535 | CRIT 9.1 | apache http_server A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes t | 0.5% | — |
| CVE-2026-42252 | CRIT 9.1 | apache airflow Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag | 0.4% | — |
| CVE-2026-41919 | CRIT 9.1 | apache ofbiz Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.5% | — |
| CVE-2026-41225 | CRIT 9.1 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Suppo | 0.3% | — |
| CVE-2026-41103 | CRIT 9.1 | microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | 5.4% | — |
| CVE-2026-41041 | CRIT 9.1 | apache gravitino URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. | 0.6% | — |
| CVE-2026-40982 | CRIT 9.1 | vmware spring_cloud_config Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin | 0.7% | — |
| CVE-2026-40976 | CRIT 9.1 | vmware spring_boot In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and re | 0.5% | — |
| CVE-2026-40682 | CRIT 9.1 | apache opennlp XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load tim | 0.5% | — |
| CVE-2026-40372 | CRIT 9.1 | microsoft asp.net_core Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | 11.2% | — |
| CVE-2026-40047 | CRIT 9.1 | apache camel Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer | 2.4% | — |
| CVE-2026-40010 | CRIT 9.1 | apache wicket Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users | 0.4% | — |
| CVE-2026-39999 | CRIT 9.1 | apache apisix Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended | 0.6% | — |
| CVE-2026-34191 | CRIT 9.1 | apache apr-util Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | 0.3% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-33557 | CRIT 9.1 | apache kafka A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without valida | 0.7% | — |
| CVE-2026-33117 | CRIT 9.1 | microsoft azure_sdk_for_java The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, | 0.5% | — |
| CVE-2026-32967 | CRIT 9.1 | apache dolphinscheduler Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | 0.3% | — |
| CVE-2026-32327 | CRIT 9.1 | apache apr-util A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this | 0.5% | — |
| CVE-2026-32211 | CRIT 9.1 | microsoft azure_web_apps Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-31986 | CRIT 9.1 | apache ofbiz Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.4% | — |