57.484 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.484 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-31378 | MED 6.5 | apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.6% | — |
| CVE-2026-29220 | MED 6.5 | apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.7% | — |
| CVE-2026-29207 | MED 6.5 | apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updat | 0.5% | — |
| CVE-2026-28715 | MED 6.5 | acronis cyber_protect Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.3% | — |
| CVE-2026-27925 | MED 6.5 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. | 0.4% | — |
| CVE-2026-26929 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not a | 0.4% | — |
| CVE-2026-26155 | MED 6.5 | microsoft windows_10_1607 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0.9% | — |
| CVE-2026-26136 | MED 6.5 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-26122 | MED 6.5 | microsoft aci_confidential_containers Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-26120 | MED 6.5 | microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. | 0.6% | — |
| CVE-2026-26057 | MED 6.5 | cisco skill_scanner Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server | 0.3% | — |
| CVE-2026-25689 | MED 6.5 | fortinet fortideceptor An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, | 0.5% | — |
| CVE-2026-25219 | MED 6.5 | apache airflow The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, tho | 0.6% | — |
| CVE-2026-24888 | MED 6.5 | microsoft maker.js Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to | 0.9% | — |
| CVE-2026-24687 | MED 6.5 | umbraco umbraco_forms Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco install | 0.4% | — |
| CVE-2026-24297 | MED 6.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2026-24204 | MED 6.5 | nvidia nvflare NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure. | 0.4% | — |
| CVE-2026-24098 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later | 0.8% | — |
| CVE-2026-23985 | MED 6.5 | apache superset A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse l | 0.4% | — |
| CVE-2026-23984 | MED 6.5 | apache superset An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data | 0.3% | — |
| CVE-2026-23983 | MED 6.5 | apache superset A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these | 0.4% | — |
| CVE-2026-23982 | MED 6.5 | apache superset An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authe | 0.4% | — |
| CVE-2026-23980 | MED 6.5 | apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec | 0.6% | — |
| CVE-2026-23969 | MED 6.5 | apache superset Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was | 0.6% | — |
| CVE-2026-23889 | MED 6.5 | pnpm pnpm pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Win | 0.4% | — |