56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-59328 | MED 6.5 | apache fory A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payload that, when processed, consumes an ex | 0.6% | — |
| CVE-2025-59302 | MED 4.7 | apache cloudstack In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSeco | 0.5% | — |
| CVE-2025-59295 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | 1.8% | — |
| CVE-2025-59294 | LOW 2.1 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | 0.6% | — |
| CVE-2025-59292 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59291 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59290 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59289 | HIGH 7.0 | microsoft windows_10_21h2 Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59288 | MED 5.3 | microsoft playwright Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.2% | — |
| CVE-2025-59286 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-59285 | HIGH 7.0 | microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-59284 | LOW 3.3 | microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | 1.0% | — |
| CVE-2025-59282 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-59281 | HIGH 7.8 | microsoft xbox_gaming_services Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59280 | LOW 3.1 | microsoft windows_10_1507 Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | 0.4% | — |
| CVE-2025-59278 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59277 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-59275 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59273 | HIGH 7.3 | microsoft azure_event_grid Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. | 0.4% | — |
| CVE-2025-59272 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | 0.5% | — |
| CVE-2025-59271 | HIGH 8.7 | microsoft azure_cache_for_redis Redis Enterprise Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-59269 | MED 6.1 | f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of T | 0.3% | — |
| CVE-2025-59268 | MED 5.3 | f5 big-ip_access_policy_manager On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are no | 0.4% | — |
| CVE-2025-59261 | HIGH 7.0 | microsoft windows_11_22h2 Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59260 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. | 0.4% | — |