IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-89275 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-88773 CRIT 10.0 citrix netscaler_application_delivery_controller Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 a 0.4% —
CVE-2026-85889 CRIT 10.0 microsoft azure_ai_foundry Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-84412 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-83944 CRIT 10.0 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.4% —
CVE-2026-76460 CRIT 10.0 cisco identity_services_engine A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this v 14.0%
CVE-2026-76423 CRIT 10.0 A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authori 0.6% —
CVE-2026-76197 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit 3.5% —
CVE-2026-76195 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit 3.5% —
CVE-2026-76193 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitatio 1.3% —
CVE-2026-75723 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this 1.2% —
CVE-2026-75721 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-75703 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-75699 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-73369 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb 1.2% —
CVE-2026-70200 CRIT 10.0 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.6% —
CVE-2026-69865 CRIT 10.0 microsoft azure_container_registry Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69843 CRIT 10.0 microsoft fabric Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-69836 CRIT 10.0 microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. 1.5% —
CVE-2026-69555 CRIT 10.0 microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69502 CRIT 10.0 microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69399 CRIT 10.0 microsoft azure_arc Azure Arc Elevation of Privilege Vulnerability 0.5% —
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.9% —
CVE-2026-65816 CRIT 10.0 microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 1.0% —
CVE-2026-65801 CRIT 10.0 microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. 0.9% —