56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0285 | HIGH 10.0 | microsoft windows_nt Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. | 6.7% | — |
| CVE-1999-0233 | HIGH 10.0 | microsoft internet_information_services IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. | 16.3% | — |
| CVE-1999-0226 | HIGH 10.0 | microsoft windows_nt Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. | 5.9% | — |
| CVE-1999-0165 | HIGH 10.0 | bsdi bsd_os NFS cache poisoning. | 2.0% | — |
| CVE-1999-0119 | HIGH 10.0 | microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. | 6.0% | — |
| CVE-1999-0067 | HIGH 10.0 | apache http_server phf CGI program allows remote command execution through shell metacharacters. | 86.9% | — |
| CVE-2026-9135 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur | 0.5% | — |
| CVE-2026-8859 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl | 0.4% | — |
| CVE-2026-8635 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. | 0.3% | — |
| CVE-2026-8481 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() | 0.5% | — |
| CVE-2026-8476 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, | 0.5% | — |
| CVE-2026-64879 | CRIT 9.9 | tenable security_center A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. | 2.6% | — |
| CVE-2026-64878 | CRIT 9.9 | tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. | 0.5% | — |
| CVE-2026-62830 | CRIT 9.9 | microsoft azure_sre_agent Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-57100 | CRIT 9.9 | microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-57092 | CRIT 9.9 | microsoft windows_10_1607 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2026-54120 | CRIT 9.9 | microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50517 | CRIT 9.9 | microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2026-50515 | CRIT 9.9 | microsoft azure_service_bus Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-50481 | CRIT 9.9 | microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-48584 | CRIT 9.9 | microsoft azure_synapse Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-48326 | CRIT 9.9 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could | 0.5% | — |
| CVE-2026-47647 | CRIT 9.9 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-45499 | CRIT 9.9 | microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | 0.6% | — |