IT
57.484 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.484 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-31378 MED 6.5 apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.6%
CVE-2026-29220 MED 6.5 apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0.7%
CVE-2026-29207 MED 6.5 apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updat 0.5%
CVE-2026-28715 MED 6.5 acronis cyber_protect Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. 0.3%
CVE-2026-27925 MED 6.5 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. 0.4%
CVE-2026-26929 MED 6.5 apache airflow Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not a 0.4%
CVE-2026-26155 MED 6.5 microsoft windows_10_1607 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability 0.9%
CVE-2026-26136 MED 6.5 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-26122 MED 6.5 microsoft aci_confidential_containers Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-26120 MED 6.5 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. 0.6%
CVE-2026-26057 MED 6.5 cisco skill_scanner Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server 0.3%
CVE-2026-25689 MED 6.5 fortinet fortideceptor An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, 0.5%
CVE-2026-25219 MED 6.5 apache airflow The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, tho 0.6%
CVE-2026-24888 MED 6.5 microsoft maker.js Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to 0.9%
CVE-2026-24687 MED 6.5 umbraco umbraco_forms Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco install 0.4%
CVE-2026-24297 MED 6.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-24204 MED 6.5 nvidia nvflare NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure. 0.4%
CVE-2026-24098 MED 6.5 apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later 0.8%
CVE-2026-23985 MED 6.5 apache superset A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse l 0.4%
CVE-2026-23984 MED 6.5 apache superset An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data 0.3%
CVE-2026-23983 MED 6.5 apache superset A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these 0.4%
CVE-2026-23982 MED 6.5 apache superset An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authe 0.4%
CVE-2026-23980 MED 6.5 apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec 0.6%
CVE-2026-23969 MED 6.5 apache superset Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was 0.6%
CVE-2026-23889 MED 6.5 pnpm pnpm pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Win 0.4%