IT
57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.065 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-34176 HIGH 8.7 f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End 0.7%
CVE-2026-34059 HIGH 7.5 apache http_server Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. 0.4%
CVE-2026-34033 MED 5.4 apache answer Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authent 0.3%
CVE-2026-34032 MED 5.3 apache http_server Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. 0.5%
CVE-2026-34031 MED 6.5 apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile 0.4%
CVE-2026-34020 HIGH 7.5 apache openmeetings Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue aff 0.5%
CVE-2026-34019 MED 5.3 f5 big-ip_access_policy_manager When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  0.3%
CVE-2026-33930 MED 5.9 apache traffic_server Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0 0.4%
CVE-2026-33929 MED 4.3 apache pdfbox Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are re 0.7%
CVE-2026-33921 MED 5.2 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privi 0.1%
CVE-2026-33858 HIGH 8.8 apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended 0.6%
CVE-2026-33857 MED 5.3 apache http_server Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. 0.4%
CVE-2026-33844 CRIT 9.0 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 1.0%
CVE-2026-33843 CRIT 9.1 microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-33842 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-33841 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33840 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2026-33839 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33838 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-33837 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2026-33835 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 2.1%
CVE-2026-33834 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33833 HIGH 8.2 microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-33829 MED 4.3 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. 3.4%
CVE-2026-33828 HIGH 7.8 microsoft windows_10_1607 Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. 0.3%