56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.560 CVE
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-66803 | CRIT 10.0 | microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-65667 | CRIT 10.0 | microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-63795 | CRIT 10.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been | 0.5% | — |
| CVE-2026-63508 | CRIT 10.0 | microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-62825 | CRIT 10.0 | microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-58630 | CRIT 10.0 | microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-58275 | CRIT 10.0 | microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-58162 | CRIT 10.0 | apache traffic_server The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upg | 0.3% | — |
| CVE-2026-58150 | CRIT 10.0 | apache traffic_server Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | 0.3% | — |
| CVE-2026-57834 | CRIT 10.0 | apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or | 0.3% | — |
| CVE-2026-57106 | CRIT 10.0 | microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-56163 | CRIT 10.0 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-56162 | CRIT 10.0 | microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-48449 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | 0.5% | — |
| CVE-2026-48331 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | 0.5% | — |
| CVE-2026-48330 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v | 0.7% | — |
| CVE-2026-48323 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to | 0.6% | — |
| CVE-2026-48303 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter | 0.6% | — |
| CVE-2026-48286 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter | 0.9% | — |
| CVE-2026-47938 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | 0.4% | — |
| CVE-2026-47280 | CRIT 10.0 | microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-45480 | CRIT 10.0 | microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-42901 | CRIT 10.0 | microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0.3% | — |