IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-27246 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27245 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-27243 CRIT 9.3 adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over 0.3%
CVE-2026-24307 CRIT 9.3 microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-24305 CRIT 9.3 microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability 0.5%
CVE-2026-21264 CRIT 9.3 microsoft account Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-14973 CRIT 9.3 ibm aspera IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. 0.3%
CVE-2026-11707 CRIT 9.3 ibm tivoli_system_automation_application_manager IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. 0.2%
CVE-2025-59286 CRIT 9.3 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-59272 CRIT 9.3 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. 0.5%
CVE-2025-59252 CRIT 9.3 microsoft 365_word_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-55321 CRIT 9.3 microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-49553 CRIT 9.3 adobe connect Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that 0.6%
CVE-2025-38560 CRIT 9.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory validation An SNP cache coherency vulnerability requires a cache line eviction mitigation when validating memory after a page state change to pri 0.2%
CVE-2025-32711 CRIT 9.3 microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 8.0%
CVE-2025-29814 CRIT 9.3 microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. 2.2%
CVE-2025-22224 CRIT 9.3 vmware cloud_foundation VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach 1.6%
CVE-2024-57793 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virt: tdx-guest: Just leak decrypted memory on unrecoverable errors In CoCo VMs it is possible for the untrusted host to cause set_memory_decrypted() to fail such that an error is returned a 0.2%
CVE-2024-49147 CRIT 9.3 microsoft update_catalog Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. 1.3%
CVE-2024-49038 CRIT 9.3 microsoft copilot_studio Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. 1.0%
CVE-2024-38108 CRIT 9.3 microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability 1.2%
CVE-2024-36913 CRIT 9.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that a 0.7%
CVE-2024-36909 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail 0.2%
CVE-2024-35939 CRIT 9.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is ret 0.2%
CVE-2024-28752 CRIT 9.3 apache cxf A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the d 2.5%