IT
56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.950 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-26138 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-26125 HIGH 8.6 microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability 1.2%
CVE-2026-24302 HIGH 8.6 microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 1.5%
CVE-2026-23659 HIGH 8.6 microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-23658 HIGH 8.6 microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2026-23512 HIGH 8.6 sumatrapdfreader sumatrapdf SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Opt 0.2%
CVE-2026-23457 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but s 0.4%
CVE-2026-22742 HIGH 8.6 vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i 0.4%
CVE-2026-22729 HIGH 8.6 vmware spring_ai A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated 0.5%
CVE-2026-21333 HIGH 8.6 adobe illustrator Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim 0.2%
CVE-2026-21280 HIGH 8.6 adobe illustrator Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as pr 0.2%
CVE-2026-21272 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the syst 0.2%
CVE-2026-21271 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus 0.2%
CVE-2026-21268 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus 0.2%
CVE-2026-21267 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue req 0.7%
CVE-2026-20349 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unex 2.2%
CVE-2026-20276 HIGH 8.6 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte
CVE-2026-20273 HIGH 8.6 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple int 0.3%
CVE-2026-20271 HIGH 8.6 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0.3%
CVE-2026-20270 HIGH 8.6 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0.3%
CVE-2026-20269 HIGH 8.6 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0.3%
CVE-2026-20268 HIGH 8.6 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0.3%
CVE-2026-20230 HIGH 8.6 cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks thro 88.2%
CVE-2026-20224 HIGH 8.6 cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. 1.0%