IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-48828 MED 6.5 apache airflow The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON 0.7%
CVE-2026-48827 HIGH 7.1 apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root direc 0.5%
CVE-2026-48726 MED 6.5 apache airflow A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, 0.4%
CVE-2026-48589 MED 5.4 apache shiro Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in appli 0.4%
CVE-2026-48586 HIGH 7.5 apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is 0.6%
CVE-2026-48584 CRIT 9.9 microsoft azure_synapse Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-48583 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-48582 CRIT 9.6 microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-48581 HIGH 7.8 microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-48580 MED 5.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-48579 CRIT 9.1 microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2026-48578 HIGH 7.9 microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-48576 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1.0%
CVE-2026-48575 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-48574 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-48573 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1.0%
CVE-2026-48572 HIGH 7.0 microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-48571 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-48570 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-48569 HIGH 7.1 microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.4%
CVE-2026-48568 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2026-48566 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-48565 HIGH 7.8 microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-48564 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. 0.9%