IT
56.713 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.713 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-69400 CRIT 9.6 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-6938 MED 6.5 ibm db2 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. 0.2%
CVE-2026-69320 HIGH 8.8 microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-69306 HIGH 8.2 microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-69278 HIGH 7.8 microsoft visual_studio_code Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-69223 CRIT 9.1 apache allura Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. 0.7%
CVE-2026-6921 HIGH 8.3 google chrome Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) 0.2%
CVE-2026-6920 CRIT 9.6 google chrome Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2026-6919 CRIT 9.6 google chrome Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.3%
CVE-2026-68981 HIGH 7.5 apache nifi Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing 0.5%
CVE-2026-68980 CRIT 9.1 apache nifi Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifie 0.3%
CVE-2026-68979 CRIT 9.8 apache nifi Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing compo 0.5%
CVE-2026-68971 MED 6.5 apache airflow Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manag 0.3%
CVE-2026-68970 MED 6.5 apache airflow Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string 0.2%
CVE-2026-68969 MED 6.5 apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level 0.4%
CVE-2026-68968 HIGH 7.5 apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative 0.4%
CVE-2026-68872 MED 6.5 apache apache-airflow-providers-amazon The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo 0.3%
CVE-2026-68871 MED 6.5 apache apache-airflow-providers-apache-yandex The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in 0.3%
CVE-2026-68868 MED 6.5 apache apache-airflow-providers-google The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every 0.5%
CVE-2026-68823 CRIT 9.1 microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 0.6%
CVE-2026-68821 HIGH 7.3 microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68819 MED 5.9 microsoft windows_10_1607 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. 0.7%
CVE-2026-68817 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-68816 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-68815 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%