57.298 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-28723 | MED 4.3 | acronis cyber_protect Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-28722 | HIGH 7.3 | acronis cyber_protect Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.2% | — |
| CVE-2026-28721 | HIGH 7.3 | acronis cyber_protect Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.2% | — |
| CVE-2026-28720 | MED 4.3 | acronis cyber_protect Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-28719 | MED 4.3 | acronis cyber_protect Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-28718 | HIGH 7.5 | acronis cyber_protect Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.3% | — |
| CVE-2026-28717 | MED 5.0 | acronis cyber_protect Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.1% | — |
| CVE-2026-28716 | MED 4.4 | acronis cyber_protect Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.1% | — |
| CVE-2026-28715 | MED 6.5 | acronis cyber_protect Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.3% | — |
| CVE-2026-28714 | MED 4.8 | acronis cyber_protect Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-28712 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.1% | — |
| CVE-2026-28711 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0.1% | — |
| CVE-2026-28710 | CRIT 9.8 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.4% | — |
| CVE-2026-28709 | MED 4.3 | acronis cyber_protect Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.2% | — |
| CVE-2026-28672 | CRIT 9.8 | apache ranger Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. | 1.3% | — |
| CVE-2026-28563 | MED 4.3 | apache airflow Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authoriz | 0.4% | — |
| CVE-2026-28373 | CRIT 9.6 | stackfield stackfield The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesys | 0.4% | — |
| CVE-2026-2813 | MED 4.7 | esri arcgis_server ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to a | 0.3% | — |
| CVE-2026-2812 | MED 5.3 | esri arcgis_server ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of t | 0.4% | — |
| CVE-2026-27931 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-27930 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | 0.4% | — |
| CVE-2026-27929 | HIGH 7.0 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27928 | HIGH 8.7 | microsoft windows_server_2016 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2026-27927 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27926 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |