56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.959 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-47339 | HIGH 8.1 | apache apisix Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3 | 0.5% | — |
| CVE-2026-47304 | HIGH 8.1 | microsoft .net Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.2% | — |
| CVE-2026-46232 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device would never lie about the number of touch reports would it? If it does the loop in dualshock4_parse_report will read off the end of the to | 0.3% | — |
| CVE-2026-46138 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop | 0.3% | — |
| CVE-2026-46099 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invokin | 0.3% | — |
| CVE-2026-46010 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rxgk_extract_token() Fix a missing bit of error handling in rxgk_extract_token(): in the event that rxgk_decrypt_skb() returns -ENOMEM, it should just return tha | 0.4% | — |
| CVE-2026-45635 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-45599 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-45584 | HIGH 8.1 | microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-45503 | HIGH 8.1 | microsoft exchange_server Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 0.4% | — |
| CVE-2026-45361 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advis | 0.6% | — |
| CVE-2026-45178 | HIGH 8.1 | paloaltonetworks idira_secrets_manager Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve un | 0.4% | — |
| CVE-2026-44825 | HIGH 8.1 | apache solr Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials instal | 2.9% | — |
| CVE-2026-43865 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelca | 1.0% | — |
| CVE-2026-43377 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Don't log keys in SMB3 signing and encryption key generation When KSMBD_DEBUG_AUTH logging is enabled, generate_smb3signingkey() and generate_smb3encryptionkey() log the session, sign | 0.2% | — |
| CVE-2026-43362 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_mes | 0.2% | — |
| CVE-2026-43134 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which | 0.2% | — |
| CVE-2026-43051 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short r | 0.3% | — |
| CVE-2026-42987 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-42981 | HIGH 8.1 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-42974 | HIGH 8.1 | microsoft windows_11_23h2 Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-42945 | HIGH 8.1 | f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (f | 68.0% | — |
| CVE-2026-42900 | HIGH 8.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-42897 | HIGH 8.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 71.2% | |
| CVE-2026-42835 | HIGH 8.1 | microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | 1.3% | — |