IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-56287 HIGH 8.1 apache fineract A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation 0.7%
CVE-2026-56186 HIGH 8.1 microsoft windows_10_1607 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. 1.1%
CVE-2026-56169 HIGH 8.1 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-54995 HIGH 8.1 microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-53390 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl() validates the ACE header size and caps sid.num_subauth at SID_MAX_SUB_AUTHORITIE 0.5%
CVE-2026-53254 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers cast skb->data to protocol-specific structs without validating skb->len first. A malicious remote device can se 0.3%
CVE-2026-53178 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer un 0.3%
CVE-2026-53147 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handle_request() casts the received packet buffer to protocol-specific structs without verifying that the allocation 0.3%
CVE-2026-52967 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->Erro 0.4%
CVE-2026-5282 HIGH 8.1 google chrome Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-50694 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-50686 HIGH 8.1 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-50633 HIGH 8.1 apache cxf A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended t 0.9%
CVE-2026-50632 HIGH 8.1 apache cxf A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users 0.6%
CVE-2026-50487 HIGH 8.1 microsoft windows_11_24h2 Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50460 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-50439 HIGH 8.1 microsoft windows_10_1607 Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-50107 HIGH 8.1 f5 nginx_gateway_fabric When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Reso 0.5%
CVE-2026-49877 HIGH 8.1 apache activemq Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affec 0.5%
CVE-2026-49872 HIGH 8.1 apache apisix Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are 0.5%
CVE-2026-49402 HIGH 8.1 deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed 0.4%
CVE-2026-49297 HIGH 8.1 apache apache-airflow-providers-google Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with w 1.0%
CVE-2026-49164 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-48349 HIGH 8.1 adobe animate Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user inte 0.2%
CVE-2026-47631 HIGH 8.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.4%