IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.044 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-64080 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up a notifier callback under notify_lock, drop the lock, and then dereference the returned 0.1%
CVE-2026-62835 CRIT 9.3 microsoft azure_portal Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-62834 CRIT 9.3 microsoft azure_data_factory Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. 0.3%
CVE-2026-59118 CRIT 9.3 microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-58155 CRIT 9.3 apache traffic_server Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recom 0.4%
CVE-2026-49871 CRIT 9.3 apache apisix Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a 0.4%
CVE-2026-49798 CRIT 9.3 microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-48334 CRIT 9.3 adobe illustrator Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this is 0.4%
CVE-2026-47646 CRIT 9.3 microsoft dynamics_365_customer_voice Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-46316 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's 0.4%
CVE-2026-41920 CRIT 9.3 apache traffic_server Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue. 0.3%
CVE-2026-41106 CRIT 9.3 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-41090 CRIT 9.3 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2026-40402 CRIT 9.3 microsoft windows_11_23h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-40379 CRIT 9.3 microsoft entra_id Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2026-34691 CRIT 9.3 adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be 0.4%
CVE-2026-34615 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject maliciou 0.6%
CVE-2026-33102 CRIT 9.3 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-32210 CRIT 9.3 microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-27246 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27245 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27243 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-24307 CRIT 9.3 microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-24305 CRIT 9.3 microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability 0.5%
CVE-2026-21264 CRIT 9.3 microsoft account Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. 0.4%