IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-34327 HIGH 8.2 microsoft partner_center Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-33833 HIGH 8.2 microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-31788 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue arbitrary hypercalls from user space processes. This is normally no problem, as access is usually limi 0.2%
CVE-2026-31631 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce. 0.4%
CVE-2026-31476 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRE 0.5%
CVE-2026-27654 HIGH 8.2 f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modificat 21.0%
CVE-2026-24253 HIGH 8.2 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. 0.4%
CVE-2026-23459 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats( 0.4%
CVE-2026-23456 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checkin 0.5%
CVE-2026-22733 HIGH 8.2 vmware spring_boot Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Sec 0.4%
CVE-2026-22731 HIGH 8.2 vmware spring_boot Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue 0.3%
CVE-2026-22068 HIGH 8.2 apache traffic_server Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. 0.4%
CVE-2026-22022 HIGH 8.2 apache solr Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components.  Only deployments that 0.5%
CVE-2026-21535 HIGH 8.2 microsoft teams Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-21532 HIGH 8.2 microsoft azure_functions Azure Function Information Disclosure Vulnerability 0.8%
CVE-2026-21227 HIGH 8.2 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-20045 HIGH 8.2 cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection 4.4%
CVE-2026-14996 HIGH 8.2 ibm aspera_faspex IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. 0.2%
CVE-2025-71311 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked 0.3%
CVE-2025-71072 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: shmem: fix recovery on rename failures maple_tree insertions can fail if we are seriously short on memory; simple_offset_rename() does not recover well if it runs into that. The same goes fo 0.3%
CVE-2025-68365 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use KMSAN reports: Multiple uninitialized values detected: - KMSAN: uninit-value in ntfs_read_hdr (3) - KMSAN: uninit-value in bcmp (3) Memory 0.4%
CVE-2025-66675 HIGH 8.2 apache struts Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1 0.6%
CVE-2025-64677 HIGH 8.2 microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-59292 HIGH 8.2 microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59291 HIGH 8.2 microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. 0.4%