IT
57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.921 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-65084 HIGH 8.1 nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and es 0.4%
CVE-2026-65081 HIGH 8.1 nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, inform 0.3%
CVE-2026-64444 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP 0.3%
CVE-2026-64443 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a m 0.3%
CVE-2026-64442 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_ 0.3%
CVE-2026-64440 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct HT_caps_ 0.3%
CVE-2026-64398 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after checking 0.5%
CVE-2026-64368 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even i 0.4%
CVE-2026-64235 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform (eg: Skylake), with retbleed=stuff, registe 0.3%
CVE-2026-64223 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTLM maps ieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements against the number of link-map entries indicated by link_map_ 0.3%
CVE-2026-64176 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as 7265D, rates are still encoded in version 1 format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but 0.2%
CVE-2026-63520 HIGH 8.1 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. 2.9%
CVE-2026-63042 HIGH 8.1 apache inlong Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advis 0.5%
CVE-2026-63040 HIGH 8.1 apache inlong Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Use 0.5%
CVE-2026-62889 HIGH 8.1 microsoft windows_10_1607 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-62820 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-62819 HIGH 8.1 microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine 0.6%
CVE-2026-62792 HIGH 8.1 microsoft windows_10_1607 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-62781 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-62778 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-62418 HIGH 8.1 apache syncope Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. 0.5%
CVE-2026-62391 HIGH 8.1 apache kyuubi The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache 0.5%
CVE-2026-59286 HIGH 8.1 vmware spring_for_graphql The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Sp 0.2%
CVE-2026-59285 HIGH 8.1 vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 0.5%
CVE-2026-59245 HIGH 8.1 apache apache-airflow-providers-fab In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs 0.6%