IT
56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.721 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-67552 HIGH 7.5 apache qpid_proton-dotnet A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the i 0.5%
CVE-2026-67551 HIGH 7.5 apache qpid_proton-dotnet pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fi 0.5%
CVE-2026-67465 HIGH 7.5 apache qpid_proton-dotnet A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes 0.5%
CVE-2026-67260 HIGH 7.3 apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug 0.8%
CVE-2026-66909 CRIT 9.8 apache cxf Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized obj 0.7%
CVE-2026-66908 HIGH 7.5 apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe 0.4%
CVE-2026-66907 HIGH 7.5 apache camel Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud Stor 0.4%
CVE-2026-66906 CRIT 9.1 apache camel Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Az 0.4%
CVE-2026-66810 MED 5.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66809 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66808 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.1%
CVE-2026-66807 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-66806 MED 5.5 microsoft 365_apps Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66805 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.5%
CVE-2026-66804 HIGH 7.8 microsoft windows_10_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 5.3%
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-66802 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-66800 HIGH 8.6 microsoft azure_data_factory Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-66799 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-66797 MED 5.4 apache cloudstack Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result corr 0.1%
CVE-2026-66756 CRIT 9.8 apache tika Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. 0.4%
CVE-2026-66755 HIGH 7.5 apache tika Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible 0.4%
CVE-2026-66722 HIGH 7.2 apache cloudstack Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just th 0.3%
CVE-2026-66721 LOW 2.7 apache cloudstack Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. 0.2%
CVE-2026-66713 CRIT 9.8 apache axis2\/java Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthentic 1.0%