IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-57239 HIGH 8.2 foxit pdf_editor The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. 0.2%
CVE-2026-53268 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This h 0.3%
CVE-2026-50680 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50528 HIGH 8.2 microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.6%
CVE-2026-50429 HIGH 8.2 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2026-50338 HIGH 8.2 microsoft azure_spring_cloud Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-48345 HIGH 8.2 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0.9%
CVE-2026-48290 HIGH 8.2 adobe c2pa CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page 0.3%
CVE-2026-47877 HIGH 8.2 vmware spring_security Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 0.2%
CVE-2026-47652 HIGH 8.2 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 0.3%
CVE-2026-47623 HIGH 8.2 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. 0.4%
CVE-2026-46591 HIGH 8.2 apache camel Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-202 0.5%
CVE-2026-46303 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checkin 0.3%
CVE-2026-46037 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[] 0.4%
CVE-2026-45843 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith 0.4%
CVE-2026-45476 HIGH 8.2 microsoft azure_network_adapter Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44822 HIGH 8.2 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-43466 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fifo_pc, desync 0.3%
CVE-2026-43452 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1-byte tail reads When the last byte of options is a non-single-byte option kind, walkers that advance with i += op[i + 1] ? : 1 can read op 0.4%
CVE-2026-43365 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the superblock doesn't list a log stripe unit, we set the incore log roundoff value to 512. This leads to corrupt logs and unmountable filesys 0.4%
CVE-2026-43233 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the 0.5%
CVE-2026-43190 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without valid 0.5%
CVE-2026-41713 HIGH 8.2 vmware spring_ai A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across con 0.2%
CVE-2026-41604 HIGH 8.2 apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0.9%
CVE-2026-40022 HIGH 8.2 apache camel When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthentic 0.6%