57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-33119 | MED 5.4 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.3% | — |
| CVE-2026-33118 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-33117 | CRIT 9.1 | microsoft azure_sdk_for_java The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, | 0.5% | — |
| CVE-2026-33116 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2026-33115 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-33114 | HIGH 8.4 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-33113 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-33112 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 32.7% | — |
| CVE-2026-33111 | HIGH 7.5 | microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2026-33110 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33107 | CRIT 10.0 | microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-33105 | CRIT 10.0 | microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-33104 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33103 | MED 5.5 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | 0.2% | — |
| CVE-2026-33102 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2026-33101 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33100 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33099 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-33098 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-33096 | HIGH 7.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-33095 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-33007 | MED 5.3 | apache http_server A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fix | 0.5% | — |
| CVE-2026-33006 | MED 4.8 | apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 0.6% | — |
| CVE-2026-33005 | MED 4.3 | apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name an | 0.4% | — |