IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.831 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2025-59514 HIGH 7.8 microsoft windows_10_1607 Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59513 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-59512 HIGH 7.8 microsoft windows_10_1607 Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally. 2.9%
CVE-2025-59511 HIGH 7.8 microsoft windows_10_1809 External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59510 MED 5.5 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. 0.5%
CVE-2025-59509 MED 5.5 microsoft windows_10_1809 Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-59508 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59507 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59506 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59505 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59504 HIGH 7.3 microsoft azure_monitor_agent Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-59503 CRIT 10.0 microsoft azure_compute_resource_provider Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-59502 HIGH 7.5 microsoft windows_10_1809 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. 1.0%
CVE-2025-59501 MED 4.8 microsoft configuration_manager_2403 Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. 3.0%
CVE-2025-59500 HIGH 7.7 microsoft azure_notification_service Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-59499 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2025-59497 HIGH 7.0 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. 0.2%
CVE-2025-59494 HIGH 7.8 microsoft azure_monitor_agent Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-59489 HIGH 7.4 unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run 0.6%
CVE-2025-59483 MED 6.5 f5 big-ip_access_policy_manager A validation vulnerability exists in an undisclosed URL in the Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.3%
CVE-2025-59481 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges.  A successful exploit ca 0.4%
CVE-2025-59478 HIGH 7.5 f5 big-ip_advanced_firewall_manager When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support ( 0.3%
CVE-2025-59454 MED 4.3 apache cloudstack In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficie 0.4%
CVE-2025-59390 CRIT 9.8 apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr 0.6%
CVE-2025-59355 MED 6.5 apache linkis A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive informat 0.4%