IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-1999-0721 HIGH 7.8 microsoft windows_2000 Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. 8.5%
CVE-1999-0449 HIGH 7.8 microsoft internet_information_server The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. 49.5%
CVE-1999-0387 HIGH 7.8 microsoft windows_95 A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. 7.9%
CVE-2026-8856 HIGH 7.7 ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration. 0.2%
CVE-2026-8666 HIGH 7.7 rapid7 insightconnect_traceroute OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient inpu 1.2%
CVE-2026-8665 HIGH 7.7 rapid7 insightconnect_translate OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command constr 1.2%
CVE-2026-8660 HIGH 7.7 rapid7 insightconnect_ping OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. 1.2%
CVE-2026-8592 HIGH 7.7 rapid7 insightconnect_awk OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processi 1.2%
CVE-2026-7754 HIGH 7.7 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism. 0.3%
CVE-2026-69855 HIGH 7.7 microsoft azure_copilot Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. 0.5%
CVE-2026-66310 HIGH 7.7 microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.2%
CVE-2026-52906 HIGH 7.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of replaced Since commit 1f3e4142c0eb ("9p: convert to the new mount API"), v9fs_apply_options() applies parsed mount flags with |= onto flags al 0.1%
CVE-2026-48447 HIGH 7.7 adobe lightroom Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions be 0.1%
CVE-2026-48348 HIGH 7.7 adobe animate Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction 0.2%
CVE-2026-48347 HIGH 7.7 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0.7%
CVE-2026-47937 HIGH 7.7 adobe acrobat Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit th 0.2%
CVE-2026-47879 HIGH 7.7 vmware spring_cloud_gateway Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1. 0.2%
CVE-2026-46123 HIGH 7.7 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we poste 0.1%
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-42832 HIGH 7.7 microsoft excel Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. 0.2%
CVE-2026-33821 HIGH 7.7 microsoft dynamics_365_customer_insights Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-32174 HIGH 7.7 microsoft azure_ai_bot_service Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-27913 HIGH 7.7 microsoft windows_server_2012 Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-26147 HIGH 7.7 microsoft azure_stack_hci Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-20852 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%